Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是Anthropic公司推出了一项名为Claude Code Security的新安全功能。这个功能用于扫描用户的软件代码库,寻找漏洞并建议补丁。目前只对企业和团队客户开放。 接下来,我需要提取关键点:AI工具、扫描漏洞、建议补丁、针对企业客户、利用AI对抗威胁。这些是主要内容。 然后,我要把这些信息浓缩成一句话,不超过100字。确保涵盖所有关键点,同时语言简洁明了。 最后,检查一下是否符合用户的要求:中文总结,不使用特定的开头词,直接描述内容。确保没有遗漏重要信息。 </think> Anthropic推出Claude Code Security功能,利用AI扫描代码漏洞并建议补丁,帮助企业客户提升安全性。该工具通过模拟人类安全研究员的方式分析代码,并经过多阶段验证减少误报。开发者需手动批准修复方案以确保准确性。 2026-2-21 07:58:0 Author: thehackernews.com(查看原文) 阅读量:9 收藏

Artificial Intelligence / DevSecOps

AI-Powered Vulnerability Scanning

Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Claude Code that can scan a user's software codebase for vulnerabilities and suggest patches.

The capability, called Claude Code Security, is currently available in a limited research preview to Enterprise and Team customers.

"It scans codebases for security vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix security issues that traditional methods often miss," the company said in a Friday announcement.

Anthropic said the feature aims to leverage AI as a tool to help find and resolve vulnerabilities to counter attacks where threat actors weaponize the same tools to automate vulnerability discovery. 

With AI agents increasingly capable of detecting security vulnerabilities that have otherwise escaped human notice, the tech upstart said the same capabilities could be used by adversaries to uncover exploitable weaknesses more quickly than before. Claude Code Security, it added, is designed to counter this kind of AI-enabled attack by giving defenders an advantage and improving the security baseline.

Anthropic claimed that Claude Code Security goes beyond static analysis and scanning for known patterns by reasoning the codebase like a human security researcher, as well as understanding how various components interact, tracing data flows throughout the application, and flagging vulnerabilities that may be missed by rule-based tools.

Each of the identified vulnerabilities is then subjected to what it says is a "multi-stage verification process" where the results are re-analyzed to filter out false positives. The vulnerabilities are also assigned a severity rating to help teams focus on the most important ones.

The final results are displayed to the analyst in the Claude Code Security dashboard, where teams can review the code and the suggested patches and approve them. Anthropic also emphasized that the system's decision-making is driven by a human-in-the-loop (HITL) approach.

"Because these issues often involve nuances that are difficult to assess from source code alone, Claude also provides a confidence rating for each finding," Anthropic said. "Nothing is applied without human approval: Claude Code Security identifies problems and suggests solutions, but developers always make the call."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/02/anthropic-launches-claude-code-security.html
如有侵权请联系:admin#unsafe.sh