News
AI vulnerability research, tracked
Short, sourced summaries of what changed for open-source maintainers as AI models learned to find bugs.
October 8, 2026
Anthropic launches OSS Scanner, a free AI vulnerability scanner for open source
Opt-in projects get periodic scans by Anthropic's strongest models, including Claude Mythos, with unreviewed reports, reproducers and patches sent straight to maintainers.
October 6, 2026
Anthropic expands the Cyber Verification Program with three access tiers
Defense, Red Team and Specialized Access tiers give vetted defenders — including open-source maintainers — reduced cyber safeguards on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1.
May 22, 2026
Project Glasswing: more than 10,000 high and critical vulnerabilities in a month
Anthropic's first Glasswing update: partners using Claude Mythos Preview found over ten thousand serious bugs, and the bottleneck moved from finding vulnerabilities to fixing them.
May 17, 2026
Linux kernel sets rules for AI-assisted security reports
Short plain-text reports, verifiable impact, a tested reproducer shared on request and a tested fix with a Fixes: tag. Torvalds calls the private security list almost unmanageable.
April 29, 2026
Copy Fail (CVE-2026-31431): an AI-found Linux root exploit hidden since 2017
A logic bug in the kernel crypto API let a 732-byte Python script gain root on every mainstream distribution. It was surfaced by an AI code scanner in about an hour.
April 7, 2026
Anthropic announces Project Glasswing and Claude Mythos Preview
AWS, Apple, Google, Microsoft, the Linux Foundation and others get early access to an unreleased model that finds and exploits vulnerabilities better than all but the best humans.