Anthropics, Free

Anthropic's Free Scanner Has Flagged 29,000 Possible Security Holes — Now Comes the Hard Part

Published on 10/10/2026 at 21:41 | Editorial boerse-global.de

Anthropic's Cyber Mission pairs a free open-source vulnerability scanner with critical infrastructure protection, after models flagged 29,000+ potential flaws in six months.

Anthropic Cyber Mission: Free Open-Source Scanner, Critical Infrastructure Defense
Anthropic's Free Scanner Has Flagged 29,000 Possible Security Holes — Now Comes the Hard Part Illustration mit AI erstellt.

Anthropic launched its Cyber Mission on 8 October 2026, pairing a no-cost vulnerability scanner for open-source software with a separate protection programme aimed at critical infrastructure operators. Registered open-source projects are promised regular security reviews carried out by the company's most capable models, Claude Mythos among them.

Each generated report bundles a proof of function, an explanation of the underlying problem and, where possible, a suggested fix. One caveat sits at the centre of the design: notifications go out with no human review beforehand, which means incorrect findings can and do reach maintainers.

Isolated machines, a GitHub pull request, and a six-month haul

Getting into the scanner programme requires project maintainers to submit a pull request on GitHub containing a configuration file and a Dockerfile. To keep the investigation itself from becoming a risk, all code analysis runs inside an isolated virtual machine with no internet connection.

According to the company, its models surfaced more than 29,000 potential vulnerabilities in widely used open-source software over six months. Human reviewers then checked roughly 6,000 of those findings. Close to 5,000 unreviewed reports were passed straight to the relevant developer teams.

A report by The Hacker News put further figures on the effort: by 2 October 2026, the roughly 6,000 findings disclosed to project maintainers had produced 584 security advisories, alongside 116 pull requests.

Testing on the CyberGym platform tells a similar story of rapid improvement. Anthropic says its hit rate climbed from under 20 percent at the start of 2025 to more than 85 percent in 2026, with the company now targeting above 90 percent.

An internal sample drawn from 48 projects offers a closer look at accuracy. Of 97 findings rated high or critical, 85 — 88 percent — met the threshold for a standard disclosure process. Eleven further reports turned out to be duplicates, and just one was classified as a false alarm.

Power grids, water systems and a list of founding partners

The critical-infrastructure defence programme forms the second pillar of the Cyber Mission. Operators of electricity, water and transport networks are to receive access to Claude models, hands-on engineering support and threat analysis. Founding partners include CrowdStrike, Palo Alto Networks, Deloitte and Rockwell Automation.

Money is flowing in parallel. Anthropic is funding a set of organisations and projects across the software community, among them the Python Software Foundation, Alpha-Omega/OpenSSF, the Apache Software Foundation, Akrites and Gold Eagle.

Why finding bugs was never the bottleneck

The initiative responds to lessons from earlier security work. A previous effort, Glasswing, identified plenty of vulnerabilities without meaningfully reducing cyber risk — verifying, prioritising and actually patching the reported gaps routinely stretched across several months.

Automated security reports can also weigh down the people receiving them. On 1 October 2026, Google paused its own open-source bounty programme after a flood of largely invalid automated submissions. Rewards there had ranged from 100 to 31,337 US dollars depending on severity.

Disclaimer...

en | boerse | 70289960 |