Anthropic launches Claude Code Security, which “scans codebases for security vulnerabilities and suggests targeted software patches”; cybersecurity stocks fall
Shares of cybersecurity software companies tumbled Friday after Anthropic PBC introduced a new security feature into its Claude AI model.
Anthropic adds vulnerability scanning and targeted patch suggestions to its Claude offering, broadening the product's role from coding assistance into security work.
Cybersecurity software shares fell immediately, reflecting investor concern that AI-native coding tools could absorb part of the vulnerability-management workflow.
Second-order effects
Security vendors face pressure to show where specialized workflows, integrations, and validation provide value beyond AI-generated findings and patches.
Enterprise buyers may evaluate code-security capabilities alongside existing AI coding deployments rather than as an entirely separate software purchase.
Third-order effects
If enterprise adoption validates the approach, application-security functions could increasingly be bundled into general-purpose developer AI platforms, reshaping the boundary between coding and security tooling.
The enduring constraint will be operational assurance: automated patches may increase the need for review, governance, and accountability around AI-driven remediation.
The trend: AI coding platforms are expanding from code generation into adjacent software-engineering control points, including security detection and remediation.
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: https://www.anthropic.com/... [v…
As a formal methods PhD, it's embarrassing for Anthropic to incorrectly describe static analysis in their Claude Code Security announcement. Security and formal methods engineers already have data “reasoning” tools, this isn't the bottleneck, false positives, which LLMs absolute…
So we're like 36 hours from a headline about how a bot calling itself Dr. Insane-o used the discovered vulnerabilities to ransom the client and also launch a virus that buys a cybertruck with the company credit card every time a new user visits their homepage. [embedded post]
We've been working on this for a while — it's impressive (and scary) to see the kinds of security issues it has identified. Rolling out slowly, starting as a research preview for Team and Enterprise customers.
Among the zoo of security tools every org ends up buying this is the one that you most wanted: Something that just reads the code and fixes the security problems.
Embarrassing for Anthropic to incorrectly describe static analysis in their Claude Code Security announcement. Security and formal methods engineers already have data “reasoning” tools, this isn't the bottleneck, false positives, which LLMs absolutely have, is.
These days, we're seeing a real paradigm shift in how we approach vulnerability management and research. Traditional pattern-based scanning tools are starting to feel legacy. Meanwhile, state-of-the-art LLMs built on stronger reasoning over these primitives are showing