Anthropic Unveils Free AI Security Scanner After Uncovering 129,000 Software Vulnerabilities

Reviewed byNidhi Govil

17 Sources

Share

Anthropic launched OSS Scanner, a free AI-powered vulnerability scanner for open-source projects using its strongest models including Claude Mythos. The company also expanded its Cyber Verification Program after Project Glasswing partners discovered at least 129,000 verified vulnerabilities between April and July 2026, with over 33,000 rated critical or high severity.

Anthropic Introduces Free AI Security Scans for Open-Source Projects

Anthropic unveiled OSS Scanner, an opt-in AI-powered vulnerability scanner designed to help secure the open-source ecosystem at no cost

1

3

. Open-source projects that join will receive thorough, periodic security scans by Anthropic's strongest models, including Claude Mythos

5

. The outputs will be fully model-generated without human review or triage, enabling faster and more frequent scanning

3

. This trade-off means reports may contain false positives, but provides open-source projects with early alerts about potential security issues

1

.

Source: Hacker News

Source: Hacker News

Core maintainers can enroll by opening a pull request on the OSS Scanner's GitHub repository with a YAML configuration file that includes repository links, contact information, and a Dockerfile that sets up the environment and installs dependencies for offline security audits

3

. As of now, 116 pull requests have been submitted

3

. Anthropic expects to use criteria similar to Google OSS-Fuzz to select projects, though the process may evolve over time

3

.

Project Glasswing Uncovers Massive Scale of Software Vulnerabilities

Anthropic's partners under Project Glasswing found at least 129,000 verified vulnerabilities between April and July 2026

4

. The company's own open-source scanning efforts revealed an additional 5,500 verified vulnerabilities between April and October

2

. More than 33,000 of these vulnerabilities have been rated as critical or high severity

4

. Anthropic stated these figures are likely an undercount based on survey data from only a subset of Glasswing partners, and expects the true impact to be at least five times higher

2

.

By October 2, 2026, Anthropic had identified more than 29,000 candidate vulnerabilities in critical software projects, with over 6,000 flaws reported to maintainers

3

. These efforts resulted in 584 advisories

3

. However, a significant gap exists between vulnerability detection and remediation. Of 5,674 true positive vulnerabilities discovered, 3,014 are high severity and 1,522 are critical severity, yet only 516 have been patched

2

.

Expanded Cyber Verification Program With Three-Tier Access

Anthropic reconfigured its Cyber Verification Program by merging Project Glasswing and the original CVP into one expanded offering with three distinct tiers

2

4

. All three tiers include access to Claude Opus 5.5, Sonnet 5.5, Claude Mythos 5.1, and future models

4

. The restructuring ties model capabilities to specific tasks while varying the level of safeguard restrictions across tiers

2

.

Source: Hacker News

Source: Hacker News

Defense Access is intended for security teams at companies, nonprofits, universities, and government organizations focusing on system defense, incident response, and malware analysis

2

4

. In testing with CyScenarioBench challenges, Claude Opus 5.5 faced refusals in 46 of 50 attempts under Defense Access

2

. Red Team Access is designed for authorized penetration testing and offensive cyber evaluation, with organizations able to apply for this tier

4

. Under red team safeguards, Claude Opus 5.5 completed 34 of 50 tasks

2

.

Specialized Access has the fewest restrictions and is reserved for a limited set of verified organizations authorized to test safety-critical systems such as power grids, flight operating systems, telecom networks, and interbank transfer infrastructure

2

4

. Anthropic vets each member together with the US government, and existing Glasswing members will transition into this tier

4

.

Why AI-Driven Security Tools Matter for Critical Infrastructure

Both Anthropic and Google recognize the strategic importance of securing open-source code that underpins the internet, often maintained by unpaid workers

5

. Vulnerabilities in open-source software pose significant risks, exemplified by the XZ Utils backdoor that could have granted hackers administrative control over millions of systems worldwide

5

. AI tools have already helped identify major security flaws like the "Copy Fail" bug that impacted nearly every Linux distribution in May

1

.

Source: Axios

Source: Axios

Anthropic launched its Critical Infrastructure Defense Program to safeguard critical infrastructure and open-source software as part of its broader Cyber Mission

3

. With AI increasingly equipping threat actors to discover and exploit vulnerabilities faster and at scale, the initiative aims to arm defenders with AI-driven security tools to combat threats, accelerate fixes, and explore secure architectures

3

. Anthropic forecasts that within two years, AI security will favor defense, making it easier to catch bugs before deployment, write fundamentally secure software, and actively defend systems with models

3

. However, some open-source projects are already struggling with the sudden influx of AI-generated bug reports

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved