Anthropic Launches OSS Scanner: Using AI to Provide Free Vulnerability Scanning for Open-Source Software
The Block
1h ago
Ai Focus
Anthropic announced on October 8th local time the launch of an optional vulnerability detection service OSS Scanner for open-source software. By joining the project, core maintainers of eligible open-source projects can receive regular free security scans provided by its AI model. The scan results are automatically generated by the large model without any manual review process.
Helpful
No.Help

On October 9th, according to news from the IT community, on October 8th local time, Anthropic officially launched an optional vulnerability detection service OSS Scanner for open-source software. Open-source projects that join this initiative will receive comprehensive and free regular security scans provided by Anthropic's most powerful AI models (including Claude Mythos).

Eligible core maintainers of open-source projects only need to submit a pull request to the OSS Scanner GitHub repository ( PR ) following the standard project template to complete the application for integration. The review criteria are similar to Google's OSS-Fuzz, with priority given to fundamental open-source projects that have a significant impact on critical infrastructure and user security.

According to the introduction, over the past six months, Anthropic has used the latest models to conduct vulnerability scans on multiple core software projects around the world, detecting more than 29,000 potential vulnerabilities. Due to limited manpower, Anthropic was only able to manually review and assess about 6,000 of these vulnerabilities.

As mentioned by Anthropic, they will continue to submit manually verified vulnerability reports through the existing coordination and vulnerability disclosure process (CVD). At the same time, an optional "fast track" has also been established for teams that wish to obtain detailed information as soon as possible after the vulnerability reports are produced.

IT has learned that the scanning results of OSS Scanner are entirely generated automatically by large models, without any manual review or grading process. In the past few weeks, Anthropic has completed practical tests of this automated detection process in dozens of open-source projects.

To verify an early version of OSS Scanner, Anthropic entrusted senior penetration testing experts responsible for auditing CVD to manually review 97 severe and high-risk vulnerabilities detected by the scanner in 48 projects.

Among these vulnerabilities, 85 (accounting for 88%) met the criteria to enter the CVD disclosure process. Of the remaining 12 detected items, 11 indeed existed but were either known defects or overlapped with other results from this scan; ultimately, only 1 case was determined to be an invalid report (false positive).

As mentioned by Anthropic, it is not possible to guarantee that this scanner is absolutely perfect and error-free, but in the future, we will continue to refine and optimize the entire detection system based on the feedback from maintenance personnel and with the continuous iteration of the underlying models.

Tip
$0
Like
0
Save
0
Views 17
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Under pressure of performance, a large purchase of 20,000 NVIDIA GPU Tianyang Technology shares led to a price increase of over 12%
On October 9, Tianyang Technology disclosed that it had signed a GPU procurement agreement with Company X to purchase 20,000 NVIDIA RTX PRO units at 5,500 Blackwell each, resulting in a 12.38% increase in the closing stock price. The article stated that this product is not a AI training chip for data centers, and based on market prices, the value of this procurement is estimated to be between 1.6 billion and 2.4 billion yuan.
The Block
·2026-10-09 16:42:57
0
XRP Testing the $1.32 support level, ETF Demand slowing down
After failing to break through the $1.60 resistance level, XRP has seen a cumulative decline of nearly 7% in 7 days. Analysts note that since October, XRP ETF has only recorded approximately $4 million in net inflows, which is significantly lower than the $121.4 million in September; meanwhile, the inflows into exchanges for XRP have risen to their highest level since July 2026, increasing concerns in the market about profit-taking.
CoinJournal
·2026-10-09 16:35:48
8
CaixaBank Expands Strategic Cooperation with Google Cloud to Accelerate the Construction of AI and Data Capabilities
CaixaBank Announces Expansion of Strategic Agreement with Google Cloud, Extending Cooperation Until 2033, Focusing on Advancing Artificial Intelligence, Data Management, Data Analysis, and Cloud Infrastructure Capacity Building. According to the company, the new agreement will incorporate Gemini Enterprise, and will revolve around three main pillars: data analysis and proxy AI, hybrid infrastructure and security, and employee training and empowerment.
PR Newswire
·2026-10-09 16:12:09
20
Apple reportedly cuts orders for iPhone 18% to 20% of Pro series components; rising prices of memory chips drag down demand for new devices
Insiders say that Apple has informed some suppliers to cut the production of iPhone by 18%, Pro by 18%, and iPhone by 18%. The order volume in October has decreased by 15% to 20% compared to the original plan. Reports indicate that rising prices of components such as storage chips have pushed up the selling prices of new devices, and coupled with demand falling short of expectations, this has prompted Apple to lower its shipment forecasts. Additionally, the competition in the AI industry for storage capacity may continue to put pressure on the costs of consumer electronics until 2027.
The Block
·2026-10-09 15:52:01
19
Liquid AI Open-source d1 Series Decision Models: Single Judgment Takes Only 8 Milliseconds, Supports Image Input
Liquid AI announced on October 7 the launch of two open-weight decision-making models, d1-3B and d1-omni-600M, which support text and image input, as well as text, image, and voice input respectively. The company claims that d1-3B leads all models under 10B in the public test set, and achieves an inference speed of 8 milliseconds for a single question on RTX 4090.
The Block
·2026-10-09 15:51:59
16
View More