使前沿网络安全能力可供防御者使用。
Making frontier cybersecurity capabilities available to defenders

原始链接: https://www.anthropic.com/news/claude-code-security

## Claude 代码安全:AI 驱动的漏洞检测 Anthropic 发布了 **Claude 代码安全**的有限研究预览版,这是 Claude 代码中的一项新功能,旨在主动识别并帮助修复软件漏洞。与依赖已知模式的传统静态分析工具不同,Claude 代码安全 *像人类安全研究人员一样* 推理代码,从而发现常规方法常常遗漏的复杂、上下文相关的缺陷。 该系统不会自动应用修复;相反,它会标记潜在问题,并提供严重程度评级和建议的补丁,以供**人工审查和批准**。多阶段验证过程可最大限度地减少误报,置信度评分可帮助团队确定优先级。 Claude 代码安全经过广泛的研究开发——包括在开源代码中发现 500 多个先前未检测到的漏洞——旨在增强防御者对抗日益复杂、AI 驱动的攻击的能力。 目前,此预览版面向企业和团队客户提供(开源维护者可获得加速访问),旨在寻求协作反馈,以完善该工具并促进负责任的部署,从而构建更安全的编码环境。

Hacker News 新闻 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 让前沿网络安全能力惠及防御者 (anthropic.com) 10 分,由 surprisetalk 发表于 27 分钟前 | 隐藏 | 过去 | 收藏 | 2 条评论 帮助 upghost 发表于 6 分钟前 | 下一个 [–] 阿纳金:我要用我的 AI 漏洞扫描器拯救世界,帕德梅。 帕德梅:你是扫描漏洞来修复它们,阿纳金? 阿纳金:…… 帕德梅:你是扫描漏洞来修复它们,对吧,安妮? 回复 drcongo 发表于 1 分钟前 | 上一个 [–] 我以为他们已经注意到我消耗了多少 Claude 代币来构建防御措施,以对抗 AI 机器人蜂群。 令人遗憾的是,他们没有。 回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

Claude Code Security, a new capability built into Claude Code on the web, is now available in a limited research preview. It scans codebases for security vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix security issues that traditional methods often miss.

Security teams face a common challenge: too many software vulnerabilities and not enough people to address them. Existing analysis tools help, but only to a point, as they usually look for known patterns. Finding the subtle, context-dependent vulnerabilities that are often exploited by attackers requires skilled human researchers, who are dealing with ever-expanding backlogs.

AI is beginning to change that calculus. We’ve recently shown that Claude can detect novel, high-severity vulnerabilities. But the same capabilities that help defenders find and fix vulnerabilities could help attackers exploit them.

Claude Code Security is intended to put this power squarely in the hands of defenders and protect code against this new category of AI-enabled attack. We’re releasing it as a limited research preview to Enterprise and Team customers, with expedited access for maintainers of open-source repositories, so we can work together to refine its capabilities and ensure it is deployed responsibly.

How Claude Code Security works

Static analysis—a widely deployed form of automated security testing—is typically rule-based, meaning it matches code against known vulnerability patterns. That catches common issues, like exposed passwords or outdated encryption, but often misses more complex vulnerabilities, like flaws in business logic or broken access control.

Rather than scanning for known patterns, Claude Code Security reads and reasons about your code the way a human security researcher would: understanding how components interact, tracing how data moves through your application, and catching complex vulnerabilities that rule-based tools miss.

Every finding goes through a multi-stage verification process before it reaches an analyst. Claude re-examines each result, attempting to prove or disprove its own findings and filter out false positives. Findings are also assigned severity ratings so teams can focus on the most important fixes first.

Validated findings appear in the Claude Code Security dashboard, where teams can review them, inspect the suggested patches, and approve fixes. Because these issues often involve nuances that are difficult to assess from source code alone, Claude also provides a confidence rating for each finding. Nothing is applied without human approval: Claude Code Security identifies problems and suggests solutions, but developers always make the call.

Using Claude for cybersecurity

Claude Code Security builds on more than a year of research into Claude’s cybersecurity capabilities. Our Frontier Red Team has been stress-testing these abilities systematically: entering Claude in competitive Capture-the-Flag events, partnering with Pacific Northwest National Laboratory to experiment with using AI to defend critical infrastructure, and refining Claude’s ability to find and patch real vulnerabilities in code.

Claude’s cyberdefensive abilities have improved substantially as a result. Using Claude Opus 4.6, released earlier this month, our team found over 500 vulnerabilities in production open-source codebases—bugs that had gone undetected for decades, despite years of expert review. We’re working through triage and responsible disclosure with maintainers now, and we plan to expand our security work with the open-source community.

We also use Claude to review our own code, and we’ve found it to be extremely effective at securing Anthropic’s systems. We built Claude Code Security to make those same defensive capabilities more widely available. And since it’s built on Claude Code, teams can review findings and iterate on fixes within the tools they already use.

The road ahead

This is a pivotal time for cybersecurity. We expect that a significant share of the world’s code will be scanned by AI in the near future, given how effective models have become at finding long-hidden bugs and security issues.

Attackers will use AI to find exploitable weaknesses faster than ever. But defenders who move quickly can find those same weaknesses, patch them, and reduce the risk of an attack. Claude Code Security is one step towards our goal of more secure codebases and a higher security baseline across the industry.

Getting started

We’re opening a limited research preview of Claude Code Security to Enterprise and Team customers today. Participants will get early access and collaborate directly with our team to hone the tool’s capabilities. We also encourage open-source maintainers to apply for free, expedited access.

Apply for access here.

To learn more, visit claude.com/solutions/claude-code-security.

联系我们 contact @ memedata.com