
Anthropic
AI Security · Open Source · Cybersecurity
Anthropic launches free OSS Scanner to hunt open-source vulnerabilities
October 8, 2026
Skipping human review entirely, the reports trade speed for accuracy as exploit development shrinks to minutes.
- Anthropic launched OSS Scanner on October 8, 2026, an opt-in service that runs its strongest models, including Claude Mythos, against enrolled open-source repositories to find vulnerabilities at no cost.
- Unlike Anthropic's existing disclosure process, which has manually reviewed only about 6,000 of 29,000 candidate vulnerabilities found over six months, OSS Scanner reports are fully model-generated with no human triage, trading verification for speed.
- On the CyberGym benchmark, Anthropic says LLMs' vulnerability-detection rate jumped from under 20% in early 2025 to over 85% in 2026.
- Maintainers enroll by submitting a GitHub pull request with a Dockerfile that lets Anthropic's offline agents build and audit the project without internet access.
- OSS Scanner launched alongside a new Anthropic Cyber Mission that also includes a Critical Infrastructure Defense Program for power grids and water systems, with eleven founding partners including Accenture, Booz Allen, CrowdStrike and Palo Alto Networks.
- In a pre-launch validation exercise, expert penetration testers judged 85 of 97 critical and high-severity model-generated findings across 48 projects (88%) to be valid.
- The move signals AI labs shifting from assisting human-reviewed bug bounties to autonomous, continuous scanning, intensifying a race where both defenders and attackers can exploit the same newfound speed.