Skip to content

SecurityIndependently confirmed2 publishers2 min readPublished

Anthropic sends unreviewed AI bug reports with proofs of concept to open source maintainers

Anthropic expects more than 90% of the unreviewed vulnerability reports its new OSS Scanner sends to open source maintainers to be real. Opt-in projects get findings faster and take on the work of catching the errors, such as wrong severity ratings.

The Watch · Security desk

How we use AISend a correction

What happened

  • Each report explains the suspected flaw, includes a proof of concept showing how it could be exploited, and suggests a fix when one exists.
  • OSS Scanner is free, modeled on Google's OSS-Fuzz, and uses Anthropic's most capable models to scan enrolled projects periodically.
  • Anthropic built the service after some maintainers who triage at scale asked for everything its models had found, unreviewed findings included.
  • Projects that stay out keep receiving human-verified disclosures through Anthropic's coordinated vulnerability disclosure process.
  • A separate Critical Infrastructure Defense Program has 11 OT security providers as founding partners, among them Dragos, Rockwell Automation and CrowdStrike.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost By Anthropic's own forecast, up to one report in ten is wrong, and the maintainer who opted in spends the hours working out which ones.
  • decision Maintainers now choose between machine findings at speed and the slower human-checked track, and the choice depends on whether they have the triage staff to absorb the volume.
  • constraint In OT, faster discovery adds to a backlog that can take years to clear, because the affected systems often cannot be taken offline to patch.

Anthropic gives the 90% figure as an expectation and says it aims to raise it over time [7]. At that floor, up to about one report in ten would describe a flaw that is not there [17]. Anthropic's own list of inaccuracies to expect includes wrong severity ratings [8]. "The reports are model-generated and sent without human review," Anthropic said [3].

Taking out the reviewer is deliberate. Skipping review gets reports to maintainers faster, according to the company [8]. Anthropic says finding vulnerabilities has never been easier, while verifying, prioritizing and patching them is still hard [9]. Flaws found through its earlier Project Glasswing often took months to fix, and the company admitted Glasswing has not yet cut cyber risk enough [10]. OSS Scanner drops Anthropic's own verification step, one of the hard parts on that list. Projects that say they can keep up with the findings do that work themselves [5].

For operators, the effect shows up in their dependencies. Opt-in projects will hear about flaws sooner [8]. Whether fixes ship sooner depends on each maintainer's triage capacity. The only fix-time evidence Anthropic offered is the Glasswing record of months-long fixes [10]. The announcement as reported does not say how many projects have enrolled or how reports, proofs of concept included, reach maintainers.

Patch cycles in OT are longer still. Anthropic noted that OT systems often cannot be taken offline for patching, so known vulnerabilities can stay open for years. In rare cases, it said, a patch could take decades to apply safely [14]. Through the Critical Infrastructure Defense Program, the companies that handle OT security for power, water, manufacturing and transportation operators get access to Anthropic's frontier Claude models, its threat research and engineers working on site [12]. Several partners already use Claude to fix vulnerabilities and help customers do the same, according to Anthropic [16]. It is starting with a small group and plans to add partners and sectors in the coming months [15].

What to watch

  • A measured true-positive rate from Anthropic for OSS Scanner reports, replacing the above-90% expectation.
  • Time-to-fix figures from opt-in projects, set against the months-long fixes Anthropic reported for Glasswing findings.
  • Whether the CIDP grows past its first 11 partners into the additional sectors Anthropic says it will add in the coming months.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption25
Hype gap+10
Incentives60
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Anthropic on Thursday announced two new cybersecurity initiatives: one gives open source maintainers faster access to AI-generated vulnerability reports, and the other targets companies that help secure operational technology (OT).

  2. [2]

    OSS Scanner, inspired by Google's OSS-Fuzz, is a free service that uses Anthropic's most capable models to periodically scan open source projects; maintainers have to opt in to have their projects scanned.

  3. [3]

    "The reports are model-generated and sent without human review," Anthropic said.

    ReportedSupportedSource: Anthropic, via SecurityWeek2 sources— create a free account to open themView cited source

Sources

2 independent publishers whose own reporting we read for this story.

  1. helpnetsecurity.com

    1 article · October 9, 2026

    Anthropic offers free AI security scans to open-source maintainers
  2. securityweek.com

    2 articles · October 9, 2026

    Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security - SecurityWeek

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories