What happened
On Oct 8 Anthropic's Frontier Red Team launched OSS Scanner, an opt-in service that gives eligible open-source projects periodic, fully model-generated security audits at no cost, produced by its strongest models including Claude Mythos. Validation of an early version: 85 of 97 (88%) critical/high findings across 48 projects met Anthropic's CVD bar; early disclosures to PostgreSQL, OpenSSL, wolfSSL, curl, and HotCRP maintainers included chained unauthenticated-RCE exploits with reproducers and candidate patches, plus 5 CVEs from 74 wolfSSL reports.
Why it matters
This scales the Frontier Red Team's bottlenecked manual vuln-disclosure pipeline into a free ecosystem-wide service, letting maintainers receive raw-model reports (with exploits and patches) as fast as the LLM finds them — an order-of-magnitude change in who gets AI vuln discovery first, set against attackers who can weaponize the same models in minutes.
Applicability
Core maintainers of eligible open-source projects should opt in immediately; security leaders and OSS foundations should track which critical dependencies submit and watch for the fast-track report flow.