The Maivia Gazette

Verified AI news, every morning

Security

Anthropic launches a free scanner that sends unreviewed AI bug reports to open-source maintainers, and pairs with 11 firms on critical infrastructure

OSS Scanner sends model-written vulnerability reports and proof-of-concept exploits to projects that opt in. Anthropic says flaws found through Project Glasswing often took months to fix.

Paper capsules pile up from pneumatic tubes onto a wooden workbench in a sunlit library workshop.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.

Anthropic announced two cybersecurity initiatives on Thursday. The first, OSS Scanner, is a free service inspired by Google's OSS-Fuzz. It uses Anthropic's most capable models, which The Verge reports include Mythos, to scan open-source projects at regular intervals. Maintainers have to opt in. Each report explains the suspected vulnerability, includes a proof-of-concept exploit and, when one is available, suggests a fix. The reports go to maintainers without human review. Anthropic says human validation had become a bottleneck, so maintainers now have to check the findings and decide what to fix first. The company built the service after some maintainers asked for everything its models had found in their projects. An early version of the scanner produced 97 high- and critical-severity findings across 48 projects, which penetration testers then assessed. According to Anthropic, 85 met its coordinated disclosure criteria and 11 were real but duplicated known issues. Anton Arapov of OpenSSL Corporation said the raw reports were as good as, and sometimes better than, reports written by people. The second initiative is a critical infrastructure defense program. It pairs Claude models, Anthropic engineers and threat research with 11 companies: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic says the programs build on Project Glasswing. It acknowledges that finding vulnerabilities has become easy, but that verifying and patching them is still slow.

Sources

  1. SecurityWeekAnthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecurityPublished · fetched
  2. Help Net SecurityAnthropic offers free AI security scans to open-source maintainers - Help Net SecurityPublished · fetched
  3. CyberScoopAnthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source softwarePublished · fetched
  4. The VergeAnthropic launches free AI security scans for open-source projectsPublished · fetched

Also in this edition