Skip to content

anthropic

Anthropic's OSS Scanner skips human review on bug reports

Promtime

Some open-source maintainers asked Anthropic for everything its models had found in their code, reviewed or not, and Anthropic has turned that request into a product. OSS Scanner, one of two programs in the Anthropic Cyber Mission announced by Anthropic, sends free, model-written vulnerability reports to opt-in projects without a human checking them first.

At a glance

  • The Cyber Mission has two tracks for now: OSS Scanner for open-source projects and the Critical Infrastructure Defense Program, which serves the providers that protect power grids, water systems and transport networks.
  • Each scanner report carries a proof of concept, an explanation and a suggested fix where one exists, and Anthropic expects a true-positive rate above 90% across the findings it sends.
  • The catch is twofold: without human review some reports will be wrong, for example on severity, and in Project Glasswing months often passed between finding a bug and fixing it.

If you have not been following, Project Glasswing is where this started. According to Anthropic, it launched on April 7, 2026 around Claude Mythos Preview, an unreleased model the company said could surpass all but the most skilled humans at finding and exploiting software vulnerabilities. Earlier this week Anthropic merged Glasswing into its expanded Cyber Verification Program, which, per Anthropic, launched on October 6, 2026 with three access tiers.

OSS Scanner sends unreviewed reports, and Anthropic expects over 90% of them to be real bugs

Anthropic says OSS Scanner is inspired by Google's OSS-Fuzz, a free service that runs automated fuzz testing on open-source projects. Enrolled projects get periodic scans from Anthropic's most capable models at no cost. Each report contains a proof of concept showing how the bug could be exploited, an explanation, and a suggested fix where one is available.

The reports are generated by the model and go out without human review. That makes them faster, and Anthropic is upfront that some will contain mistakes, such as a wrong severity rating. It expects a true-positive rate above 90% and says it will work on both that rate and the quality of fixes over time.

The service is aimed at projects with the capacity to keep up with what it surfaces, and enrollment is open to core maintainers of critical open-source projects. Everyone else keeps getting human-verified disclosures under Anthropic's coordinated vulnerability disclosure policy. The Defender Advantage Fund, or 0xDAF, launched in August, supports pilot programs and keeps the scanner free.

Eleven providers, from CrowdStrike to Rockwell Automation, form the first infrastructure cohort

The second track is about operational technology: the controllers, control software and industrial networks that run power grids, water utilities, factories and transport. This equipment is built to last for decades and often cannot be taken offline to patch, so known vulnerabilities can stay open for years. It is also proprietary, and a botched change can take down a plant.

Operators of every size rely on a small set of trusted providers for this work, and the Critical Infrastructure Defense Program brings those providers frontier Claude models, on-site engineers and Anthropic's threat research. The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

Anthropic says several partners already use Claude to fix vulnerabilities and help customers do the same, and calls the small cohort a first step. Separately, since a June launch for state, local, tribal and territorial governments, it has offered Claude models and technical support to more than half of all US states and some of the largest public infrastructure operators.

Funding goes to Python, Apache and Linux Foundation security work

Alongside the scanner, Anthropic has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. It also supports Akrites and Gold Eagle, which collect and coordinate vulnerability reports from many sources so maintainers are not overwhelmed. Maintainers can apply to Claude for Open Source for free Claude Max subscriptions.

The stated roadmap has three steps: bring the scanner to more projects so findings arrive faster, automate triage and patching, which are still mostly manual, and research ways to harden or rewrite code for projects that want to go beyond patching. Anthropic says it will follow guidance from maintainers and foundations.

A proof of concept turns a report into something a maintainer can rerun

Anthropic's own diagnosis is that finding vulnerabilities has never been easier, while verifying, prioritizing and fixing them remains hard. A proof of concept targets the first of those steps. Think of a mechanic who hands you the worn brake pad instead of a note saying something sounds off: you can check the claim yourself rather than hunt for it.

According to a Lab Space note, Claude Mythos Preview reached an 83.1 percent success rate on the CyberGym vulnerability reproduction benchmark, and reproduction is the most labor-intensive step of triage. Build Fast with AI reports that Glasswing's first month flagged 23,019 vulnerabilities across over 1,000 open-source projects, 6,202 estimated high or critical, and that independent firms confirmed 90.6% of a 1,752-finding sample.

Patching has lagged far behind. According to the same Lab Space note, of roughly 1,596 vulnerabilities Anthropic had disclosed to open-source maintainers as of May 2026, only 97 were patched, about a six percent remediation rate.

Anthropic admits the hard part is fixing: in Glasswing months often passed between finding a bug and patching it, and with operational technology a fix may in rare cases wait decades. In our view, limiting the scanner to projects that can keep up with findings is sensible, though Anthropic does not say how it judges that capacity or how many projects have enrolled.

Eleven partners, then more sectors

Over the coming months Anthropic plans to bring the Critical Infrastructure Defense Program to more partners and more sectors, and says it will publish what it learns, including what did not work. It has not named the next sectors or given a date. Its longer forecast is that within two years AI will favor defense, while it concedes the near term may not.

Related stories

  1. Agent loop finds and fixes bugs across OpenAI systems
  2. Claude Max subscribers get up to $200 a month for the API
  3. OpenAI puts live alarms on its agents after Medicare hack
  4. A Mythos-found HFS bug was exploited a day after disclosure
  5. Claude's hillclimb cut support costs to about a fifth
  6. Anthropic's IPO filing warns its models may resist shutdown

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.