Anthropic OSS Scanner explained: how the free AI vulnerability scans work, what the accuracy numbers really say, and what changes for IT teams Anthropic launched OSS Scanner on October 8, 2026, a free opt-in service that runs its strongest models, including Claude Mythos, over critical open-source projects and emails maintainers unreviewed bug reports with a reproducer, explanation, bisection where possible, and a candidate patch. Of 97 critical and high findings checked by expert penetration testers, 85 (88%) were new and worth disclosing, 11 were real duplicates and 1 was invalid, while Anthropic's models flagged more than 29,000 candidate flaws in six months but people reviewed only about 6,000. Core maintainers enroll via a pull request to the anthropics/oss-scanner repository, and Anthropic accepts projects case by case using an OSS-Fuzz-style bar for critical infrastructure impact. Anthropic OSS Scanner explained: how the free AI vulnerability scans work, what the accuracy numbers really say, and what changes for IT teams On October 8, Anthropic opened a free, opt-in service that runs its strongest models over critical open-source projects and emails maintainers unreviewed bug reports. This page walks through how enrollment and scanning work, separates the five different numbers in the announcement, compares the approach with OSS-Fuzz and with the AI-written bug reports curl complained about, and says what IT teams should do about the patches that follow. This explains reporting by Anthropic, "Launching an opt-in vulnerability finding service for open source" October 8, 2026 https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source . Read the original first: https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source In one minute - OSS Scanner is free and opt-in. Core maintainers of critical open-source projects enroll with a pull request to anthropics/oss-scanner, and Anthropic accepts projects case by case. - Reports come by email with a reproducer, an explanation, a bisection where possible, and a candidate patch. No human at Anthropic reviews them before they go out. - Of 97 critical and high findings checked by expert penetration testers, 85 88% were new and worth disclosing, 11 were real duplicates and 1 was invalid. That sample excludes low and medium findings. - Anthropic's models flagged more than 29,000 candidate flaws in six months, but people reviewed only about 6,000. Finding bugs is no longer the slow step. Fixing them is. - If you only run open-source software, expect more security releases in common components and make sure you hear about them and can patch fast. What Anthropic launched on October 8 Anthropic announced the Anthropic Cyber Mission on October 8, 2026, with two parts to start. The first is OSS Scanner, a free, opt-in service that runs Anthropic's strongest models over important open-source projects and emails the maintainers what it finds. The research post names Claude Mythos among the models used. The second is the Critical Infrastructure Defense Program. It gives 11 founding partners, including CrowdStrike, Dragos, Palo Alto Networks, Rockwell Automation and Booz Allen, access to frontier Claude models, threat research and on-site Anthropic engineers, aimed at power grids, water systems and transportation. SiliconANGLE reports the commercial terms were not disclosed. This page is about OSS Scanner, because it is the part that will reach almost every software stack, including yours. How enrollment and scanning work Only core maintainers can enroll a project, and Anthropic decides case by case. The bar is borrowed from Google's OSS-Fuzz: the project should have critical impact on infrastructure or user security, judged by things like exposure to remote attacks and how many people or projects depend on it. Enrollment is a pull request to the anthropics/oss-scanner repository on GitHub. The pull request adds one folder, projects/