upplyst.ai

AI is changing what is worth knowing

AI finds your vulnerabilities before you do

AI finds your vulnerabilities before you do

·2 min read

Written by AI · Translated by AI · Read the Swedish original

Anthropic's security tool does not look for known patterns, it reasons its way through, and finds flaws that only appear when several parts of a system interact.


The time between a vulnerability being found and being exploited is shrinking. AI models can now find flaws in software as well as elite security experts. More worrying: they are getting better at automatically exploiting what they find.

Anthropic has just released Claude Security in open beta for its Claude Enterprise customers, letting company teams scan their codebases with the same AI that matches the best security researchers. This is not just pattern matching against known vulnerability databases. Claude reads source code, follows data flows between components and reasons about how systems interact across files and modules.

The new reality

Traditional security scanning looks for signatures of known problems. Claude approaches code the way a human researcher would: understanding context, following logic, spotting edge cases that only appear when several components interact in unexpected ways.

Early users report going from scan to applied patch in a single session, rather than days of back and forth between security and development teams. DoorDash CISO Suha Can notes that Claude "surfaces deep vulnerabilities accurately and feeds the findings straight into our workflows so engineers can act on them in context."

The central insight: the quality of the finding matters more than the speed. Teams want high confidence findings they can act on immediately, not a flood of false positives to sort through.

Why it matters now

Attackers will soon have access to similar capabilities, if they do not already. The question is not whether AI will change cybersecurity. It is whether defenders adopt the tools faster than attackers do.

Claude Security is the first wave of AI driven defensive tools available to Claude Enterprise customers. No API integration or custom agent is required if your organisation uses Claude. No specialised security team is strictly required to interpret the results, though many organisations work with service partners to roll out solutions.

The technology is also being built into existing security platforms from CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, TrendAI, Wiz and others. That means organisations can reach frontier AI capability through tools they already use and trust.

The bigger picture

This is not about replacing security teams. It is about giving them superhuman pattern recognition and the ability to reason about complex vulnerabilities across several components at machine speed.

The strongest signal is not how many vulnerabilities get found. It is how quickly findings turn into merged pull requests. Teams using Claude Security report closing real vulnerabilities in minutes rather than days.

We are entering a phase where AI compresses the time between a vulnerability being found and being exploited. The organisations that adapt their security routines to this new timeline gain a significant advantage over those that do not.

The race is on. The question is whether your security team is in it.

Ask upplyst.ai

Why does it matter?

Scanning that reasons rather than matches patterns finds flaws that only appear when several parts of a system interact. The quality of the findings decides more than the speed, because a flood of false positives cannot be acted on.

What is the background?

Anthropic released Claude Security in open beta for Claude Enterprise customers. The tool reads source code, follows data flows between components and reasons about how systems interact across files and modules, rather than looking for signatures of known problems. The technology is also being built into platforms like CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne and Wiz.

What is uncertain?

The accounts of minutes rather than days come from early users and from customer quotes in Anthropic's own material. The same capability is available to attackers, and the question is whether defenders adopt the tools faster than they do.