Anthropic Expands Open Source Protection With Claude Security Scanner

0
1
Anthropic Expands Its Open-Source Security Push With Claude Security AI Vulnerability Scanner
Anthropic Expands Its Open-Source Security Push With Claude Security AI Vulnerability Scanner

Anthropic launches Claude Security, extending its open source vulnerability defence efforts to help enterprises detect, prioritise, and fix critical software flaws faster.

Anthropic has launched Claude Security, a defensive cybersecurity product now available in public beta for Enterprise-tier users, with broader access planned for Claude Team and Max tiers. Powered by Claude Opus 4.7, the tool scans codebases for vulnerabilities and generates targeted remediation guidance.

The launch extends Anthropic’s broader push to secure open-source ecosystems, building on Project Glasswing, which targets vulnerabilities in critical open-source software infrastructure. Glasswing is powered by the Mythos model—considered too powerful for public release—and is restricted to approved participants including Amazon Web Services, Google, Microsoft, and The Linux Foundation.

Claude Security can scan full repositories or targeted directories, trace data flows, analyse interdependencies, and generate patches. It assigns confidence scores and prioritises vulnerabilities by severity and impact.

“Claude reasons about code the way a security researcher does, tracing data flows, reading source code, and working out how components interact across files and modules,” Anthropic said.

To reduce noise, the system introduces a multi-stage validation pipeline with independent verification, reproduction steps, and recommended fixes, enabling teams to focus on high-impact issues first.

“We’ve added scheduled scans for ongoing coverage, the ability to dismiss findings with documented reasons… and CSV and Markdown export for integrating findings into existing tracking and audit systems,” the company added.

Anthropic has also embedded safeguards in Opus 4.7 to block malicious use cases such as ransomware development and data exfiltration, while controlled access is granted via its Cyber Verification Program.

The platform integrates with partners including CrowdStrike and Palo Alto Networks, with deployment support from Accenture and Deloitte, strengthening enterprise security posture at scale.

LEAVE A REPLY

Please enter your comment!
Please enter your name here