HeadlinesBriefing HeadlinesBriefing.com

Anthropic Offers Free Open-Source Vulnerability Scanner

Engadget •
×

Anthropic is offering open-source projects a new way to check for security flaws through its OSS Scanner. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost," the company announced. The move comes as AI models have shown they are highly capable of finding and exploiting vulnerabilities.

The scanner could give open-source developers early alerts about potential security issues without charge. However, there is a tradeoff: the reports will not be reviewed by humans. "The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage," Anthropic explained. "This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid." The reports will be generated by the company's strongest models, including Claude Mythos, to give open-source projects the largest defensive advantage.

Anthropic said the service was inspired by OSS-Fuzz, a scanner created by Google and the Open SSF (Open Source Security Foundation) that has been available since 2016. Anthropic already sells a paid product, Claude Security, which offers general-access code scanning and patching. OSS Scanner provides similar security audits at no cost.

The initiative is not purely altruistic. Both Google and Anthropic depend heavily on open-source code that underpins the internet, much of which is maintained by unpaid workers. Security flaws in such code can be highly dangerous, as shown by the XZ Utils backdoor, which could have given hackers administrative control over millions of systems worldwide.

Source: Engadget · Summarized by HeadlinesBriefing