CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • Use Cases

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

Ask AI about aVenture

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
An opt-in vulnerability-finding service for open-source software

From Anthropic

October 8, 2026

An opt-in vulnerability-finding service for open-source software

An opt-in vulnerability-finding service for open-source software
Frontier Red Team

Launching an opt-in vulnerability-finding service for open-source software

We’re launching OSS Scanner, an opt-in vulnerability scanner for the open-source ecosystem informed by our experience using Claude to find vulnerabilities during Project Glasswing. Projects that join will receive thorough, periodic security scans by our strongest models at no cost.

Language models have rapidly advanced in their ability to discover vulnerabilities, as we have reported extensively on this blog. On CyberGym, one academic vulnerability-finding benchmark, LLMs have gone from finding under 20% of vulnerabilities at the beginning of last year to finding over 85% this year. As a result, open source maintainers have gone from receiving mostly slop from LLMs to receiving high-quality bug reports.

Over the last six months, we’ve used our latest models to scan for vulnerabilities in some of the world’s most important software projects. We have discovered over 29,000 candidate vulnerabilities, but have only been able to manually review and triage approximately 6,000 of these. While 6,000 vulnerabilities is significant, we remain bottlenecked on our human capacity to validate these findings.

We are working on scaling our vulnerability disclosures. Meanwhile, with increasing frequency, maintainers who receive our first reports simply ask us for a bulk submission of all the unverified reports with proposed patches: to date, we have sent nearly 5,000 reports directly to maintainers after they asked to receive everything we had—even if it wasn’t validated. Since exploits can now be developed in minutes, projects that can find and address vulnerabilities faster can better secure their software against attackers who are racing to find and leverage these same weaknesses.

We will continue to manually disclose human-verified vulnerability reports via our existing coordinated vulnerability disclosure (CVD) process, especially for projects without the resourcing to triage reports themselves. But we are now making available an optional fast-track for those who wish to receive vulnerability reports as soon as they become available.

Our vulnerability scanner

Inspired by the positive impact on the open source ecosystem of Google's OSS-Fuzz, a project that scans open-source software for vulnerabilities with fuzzers, we are launching OSS Scanner to find vulnerabilities in open-source code with our strongest language models. While Claude Security, our general-access code scanning and patching product focuses on helping enterprises defend their systems, OSS Scanner provides security audits at no cost to open-source projects.

The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage. This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid. These reports will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage.

We have spent the last several weeks validating this pipeline with dozens of open source projects. These initial disclosures contained hundreds of bug reports, including multiple vulnerabilities that we were able to chain to unauthenticated remote code execution exploits affecting these projects. Each report contains a self-contained reproducer, explanation of the vulnerability (including a bisection to determine when the bug was introduced, where possible), and candidate patch (when available) for how the bug can be fixed. We are now making this service available to more open source projects.

Some of the feedback we received as we tested early versions of OSS Scanner and our raw model outputs:

  • “An unusually high fraction of OSS Scanner’s findings uncovered PostgreSQL defects. Several reports came with fixes we can use nearly as-is, and fast-track access let us address the newest issues before they reached a GA release.” —Noah Misch, PostgreSQL
  • “Early AI reports about 18 months ago, before Project Glasswing, were appalling. The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people. Particularly when a report comes with a real exploit attached, that's basically job done for an engineer as you can verify it right away” —Anton Arapov, OpenSSL Corporation
  • “We found the signal from these reports high: of the 74 reports we received, all but two were valid, and five became CVEs. With patches attached, the reports slotted right into our existing process to verify and fix issues. We’d love more.” —Todd Ouska, wolfSSL
  • “The bug reports were thorough and clear, with a strong understanding of HotCRP's complex permission model and good bug prioritization.” —Eddie Kohler, HotCRP

To validate an early version of OSS Scanner, we asked the expert penetration testers who review our CVD findings to check 97 critical and high-severity vulnerabilities from the scanner across 48 projects. Of these, 85 (88%) met the bar for our CVD process. Of the remaining 12, 11 were real but duplicated known issues or other findings from the scan, and only one was invalid, i.e. a “false positive.” We’ve since sent many of these findings to maintainers, who have seldom told us a high or critical finding was invalid, consistent with our prior open-source work. Some have told us severity ratings can be inflated or the scanner misunderstood the project’s threat model. We can’t guarantee the scanner will be perfect, but we’ll keep refining the system based on maintainer feedback and as models improve.

Getting started

Core maintainers of eligible projects can enroll by submitting a PR to this GitHub repo following the standard project template, with additional guidance provided in our extended FAQ. Projects are eligible based on a similar set of criteria that OSS-Fuzz uses: briefly, projects should have a “critical impact on infrastructure and user security” and we will make decisions on a case-by-case basis.

Whether or not OSS Scanner is right for you, our new Cyber Verification Program makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals. Claude for OSS provides free Claude Max 20x subscriptions to help remediate vulnerabilities and improve OSS projects.

Related content

The missing map of the sky

Astronomers have mapped the entire sky in visible light, infrared, radio, X-rays, and gamma rays. No one, however, had created a complete map of the sky in ultraviolet (UV) light. Here, Brice Ménard, an astrophysicist at Johns Hopkins University and a researcher at Anthropic, explains how he worked with Claude Science to produce the first complete map of the sky in UV light.

Read more

Claude-shaped science

Guest author Prof. Matthew Schwartz describes what happened when he stopped fighting Claude and allowed Claude to find “Claude-shaped” problems: ones best suited to the capabilities of the current generation of LLM tools. This led him to build BootLoops, a toolkit for exact calculations in quantitative science, which he has been applying across scientific fields alongside experts.

Read more

What work can robots do?

We built an index of how well today’s robots can perform US job tasks. Robots can already do three-quarters of physical tasks, mostly in limited settings, but are cost-competitive for just 0.3% of them.

Read more

Get updates on our latest red-teaming research and findings.

View original article on anthropic.com

Most Recent

Ramp Hits $60 Billion Valuation in $1.85 Billion Funding Round

Fintech startup Ramp has reached a roughly $60 billion valuation with its latest fundraising effort, according to people familiar with the matter.

Oct 9, 2026

VCs are minting decacorns at a record pace

We're in the golden age of decacorns. — The average time from launch to decacorn has been cut in nearly half, and some decacorns arrive literally overnight.

Oct 9, 2026

Ultra raises $62 million for fast-growing ‘robots as a service’ business, announces tie-up with AI research firm Physical Intelligence

Finance editor Jeff John Roberts here. The explosive growth of the robotics industry in recent years is reflected in new technology feats …

Oct 9, 2026

Tesla renames 'Full Self-Driving' to 'Tesla Assisted Driving' in Europe

The name change is enough for Germany's transport minister to start advocating for Europe-wide adoption of the driver assistance software.

Oct 9, 2026

Similar Posts

Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations

Engineers and open-source maintainers reportedly overwhelmed by thousands of sloppy reports

Oct 3, 2026

GLM-5.3 and the spread of advanced cyber capabilities

GLM-5.3 can autonomously build end-to-end cyber exploits, but unlike other frontier models, it was released without meaningful safeguards to limit misuse.

Sep 29, 2026

Socket lands $20M investment to help companies secure open source software

Socket, a startup that provides a scanning tool to detect security vulnerabilities in open source code, today announced that it raised $20 million in a Series A round led by Andreessen Horowitz (a16z). The tranche had participation from Abstract Ventures, Wndrco, Unusual Ventures and an impressively high-profile list of angel investors, including the co-founders of […]

Aug 1, 2023

Visa ships a security AI that patches production code before any human reviews it

Visa's open-source security harness now finds the vulnerability, writes the fix, and turns an adversarial panel on its own patch before any human reviews it. The whole loop ships on by default. A plain scan of the Visa Vulnerability Agentic Harness runs all 11 stages and edits source files in the ta

Aug 27, 2026