Threat reportThreat IntelligenceTL-2026-3165

Anthropic OSS Scanner: Free AI-Driven Vulnerability Scanning for Open-Source Projects (29,000+ Candidate Vulnerabilities Found)

MONITORING

Anthropic OSS Scanner (TL-2026-3165), also tracked as OSS Scanner, is a info-severity tracked intrusion set, first published 2026-10-09. It has no confirmed attribution, affects Open-source maintainers (curl, OpenSSL, wolfSSL, PostgreSQL), references 1 CVE (CVE-2026-5446), maps to 7 MITRE ATT&CK techniques (T1190, T1195.001, T1553), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
INFOAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
7MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-3165

Threat ID
TL-2026-3165
Also known as
OSS Scanner, Anthropic OSS Scanner, Claude OSS Scanner
Severity
INFO
Status
MONITORING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, open-source software, critical infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
14

Malware and tooling in Anthropic OSS Scanner

Malware and tooling: Claude Mythos, Claude Security, OSS Scanner

How Anthropic OSS Scanner works

Anthropic launched OSS Scanner on 2026-10-08, a free, opt-in Claude-based (including Claude Mythos) vulnerability-finding service for critical open-source projects. Over six months it surfaced 29,000+ candidate vulnerabilities, about 6,000 manually reviewed, with about 5,000 unverified reports sent directly to maintainers; defenders should expect higher open-source patch volume.

Anthropic announced OSS Scanner on 2026-10-08 as an opt-in vulnerability-finding service for open-source projects, reported by Security Affairs on 2026-10-09. The service applies Claude's strongest models, including Claude Mythos, with a variety of harnesses and additional token-intensive experimental harnesses, to find memory-safety, cryptographic and logic bugs in project source code. The reporting pipeline consists of vulnerability scanning, agent double-checking of each bug, candidate patch generation and root-cause analysis; maintainers then receive bundled email reports that include a reproducer, an explanation of the vulnerability, bisection analysis and a candidate patch.

Reported results: over roughly six months the scanner produced 29,000+ candidate vulnerabilities. About 6,000 were manually reviewed and triaged by Anthropic, and about 5,000 unverified, fully model-generated reports were shared directly with requesting maintainers without human review. Of 97 critical/high-severity findings validated by expert penetration testers, 85 (88%) met coordinated vulnerability disclosure (CVD) standards, 11 were duplicates of known issues and 1 was a false positive. Anthropic cites the CyberGym benchmark, where detection reportedly rose from under 20% to over 85% in about a year.

Maintainer feedback cited in the sources: Daniel Stenberg (curl) reported multiple issues including one of the worst curl vulnerabilities reported in years (no detail published); Todd Ouska (wolfSSL) said that of 74 reports all but two were valid and five became CVEs; Anton Arapov (OpenSSL) said raw model output was as good as and sometimes better than what maintainers get from people; PostgreSQL maintainers said several reports came with fixes usable nearly as-is. Earlier Anthropic-attributed wolfSSL findings include CVE-2026-5194 (missing hash, digest-size and OID checks in certificate signature verification, rated critical in reporting) and CVE-2026-5446 (ARIA-GCM nonce reuse in TLS 1.2 record encryption, rated high); the sources do not state which five CVEs OSS Scanner produced, so these are context rather than confirmed OSS Scanner output.

Program mechanics: core maintainers apply by submitting a GitHub pull request adding projects/<project>/project.yaml (repository link, contact email, Dockerfile; optional threat model, GPG key, extra CCs) to the anthropics/oss-scanner repository. Eligibility follows OSS-Fuzz-like criteria: critical impact on infrastructure and user security, exposure to remote attack (especially libraries parsing untrusted input), number of users and dependents, and a demonstrated ability to handle verified high/critical reports. Anthropic states it will not apply a 90-day disclosure period to the unvalidated findings; validated reports follow the standard 90-day CVD process. Scanning runs in hardened sandboxes with internet access disabled and reports are held in an access-restricted Anthropic cloud project.

Defender implications: no active exploitation, PoC, actor, CVSS or IOCs are stated for this item, and no CVE is attributed to it by name. It is tracked as an informational trend: AI-driven large-scale vulnerability discovery will likely increase the volume and pace of open-source patches, shrinking the window between discovery and fix, and the same capability class could be used offensively by others (Anthropic has said it does not plan general release of Claude Mythos Preview because of its cyber capabilities). Recommended actions are to prepare patch-management capacity for higher advisory volume in curl, OpenSSL, wolfSSL and similar libraries and to track upstream advisories.

MITRE ATT&CK techniques used in TL-2026-3165

Initial Access

T1190 Exploit Public-Facing Application; T1195.001 Compromise Software Dependencies and Development Tools

defense-impairment

T1553 Subvert Trust Controls

Resource Development

T1587.004 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1592 Gather Victim Host Information; T1595.002 Vulnerability Scanning

Affected products and versions in Anthropic OSS Scanner

  • Open-source maintainers (curl, OpenSSL, wolfSSL, PostgreSQL) — Downstream consumers of open-source libraries receiving AI-discovered fixes

Remediation for Anthropic OSS Scanner

Patches

  • Apply wolfSSL 5.9.1 or later (fix for CVE-2026-5194 released 2026-04-08)
  • Apply the upstream wolfSSL fix for CVE-2026-5446 (ARIA-GCM nonce reuse)

Immediate actions

  • Subscribe to upstream security advisories for curl, OpenSSL, wolfSSL, PostgreSQL and other critical open-source dependencies
  • Inventory which open-source libraries (especially TLS/crypto and untrusted-input parsers) are embedded in your products and fleet

Workarounds

  • No workaround applicable; this is an informational trend item

Longer-term hardening

  • Scale patch-management and SBOM-driven triage capacity for a higher volume of open-source advisories
  • Shorten internal SLAs for applying fixes to network-exposed libraries
  • Maintainers of critical projects: evaluate applying to OSS Scanner via a GitHub PR to anthropics/oss-scanner and prepare to triage unverified model-generated reports

CVEs associated with Anthropic OSS Scanner

CVE-2026-5446

Timeline of Anthropic OSS Scanner

  • Claude-discovered wolfSSL ARIA-GCM nonce reuse (later CVE-2026-5446) logged via static analysis in Anthropic's CVD process.
  • Anthropic announced Project Glasswing, powered by Claude Mythos Preview, with launch partners including AWS, Apple, Google, Microsoft and the Linux Foundation.
  • wolfSSL released version 5.9.1 with a patch for CVE-2026-5194 (certificate signature verification checks), reported by Anthropic's Claude Mythos Preview.
  • CVE-2026-5446 disclosed to wolfSSL maintainer, acknowledged, and patched the same day.
  • CVE-2026-5446 (ARIA-GCM nonce reuse in TLS 1.2 records) publicly revealed by Anthropic.
  • Startup Fortune reported Claude findings in wolfSSL and Cloudflare CIRCL (7 real vulnerabilities, 1 critical, 1 high, 2 medium).
  • Anthropic launched OSS Scanner, a free opt-in vulnerability-finding service for critical open-source projects, after about six months of scanning (29,000+ candidates, about 6,000 manually reviewed, about 5,000 unverified reports shared).
  • Security Affairs published coverage of OSS Scanner, citing maintainer feedback from curl, wolfSSL (five CVEs from 74 reports) and OpenSSL.

Sources cited for Anthropic OSS Scanner

Detection coverage for TL-2026-3165

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3165 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats