Anthropic launches free artificial intelligence security scanning service for open source maintainers
Anthropic has introduced a free service that uses its strongest artificial intelligence models to help open-source maintainers find and repair security vulnerabilities.
FTMQ Security, written by our newsroom0 views

Anthropic has launched the OSS Scanner, a new and free service designed to detect security vulnerabilities in open-source software, Help Net Security reported on October 9. Maintainers who opt into the program receive periodic automated scans along with reports detailing suspected flaws, reproduction steps, and potential remediation guidance. [1]
Help Net Security reported that the service expands on lessons learned from Project Glasswing, an earlier initiative that utilized the Claude model to identify software flaws. According to Anthropic, human validation processes have increasingly become a primary bottleneck in managing vulnerability reports. [1]
The development follows broader challenges across the open-source community regarding security reporting. As FTMQ Security reported earlier, Google recently froze vulnerability submissions to its open-source bug bounty program after receiving a massive influx of low-quality, automated AI reports, while the curl project closed its HackerOne bounty program for similar reasons. [4]
Anthropic operates under a governance model overseen by a Board of Directors and an independent Long-Term Benefit Trust. In 2022, the company introduced Constitutional AI, a training method that uses model feedback guided by natural-language principles instead of relying solely on human preferences. [3]
In short
- Anthropic launched a free scanning service called OSS Scanner for open-source software maintainers.
- The service builds on Project Glasswing, which previously used the Claude model to discover software flaws.
- Maintainers who enroll receive automated vulnerability reports, reproduction steps, and potential fixes.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Anthropic offers free AI security scans to open-source maintainersHelp Net Security, 1d ago (the report this story comes from)
Background
- [2]Sam Altman on Wikipedia
- [3]Anthropic on Grokipedia
- [4]Google freezes open source bug bounty program over invalid AI reports FTMQ Security, 5d ago
Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- CrowdStrike joins Anthropic initiative to secure critical infrastructure with artificial intelligenceNation State Hacking, 1h ago
- Anthropic requests voice conversation data from Claude users for model trainingTop Stories, 6d ago
More in Cybercrime and Scams
- Attackers hijack three country code domains to obtain unauthorized Google certificates1h ago
- Hackers breach ASOS systems and access customer search data1h ago
- High severity NVIDIA DCGM Exporter vulnerability threatens internet exposed GPU servers1d ago
- CISA adds actively exploited Citrix NetScaler zero day to KEV catalog5d ago
- Google freezes open source bug bounty program over invalid AI reports5d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.