Anthropic announced two new cybersecurity initiatives targeting different problems: speeding the delivery of vulnerability discoveries to open-source software project maintainers, and helping companies that secure operational technology (OT) systems used in the energy, water, manufacturing, and transportation sectors.
The initiatives are based on lessons learned from Project Glasswing, whose partners, the company said, discovered a large number of vulnerabilities but did not reduce cyber risks sufficiently. Anthropic believes that finding flaws has become easier, while validating, prioritizing, and addressing them still takes a long time; vulnerabilities found through Glasswing required months to fix.
Automatically Generated Reports Reach Developers Directly
OSS Scanner is a free service that uses Anthropic’s most capable models to scan open-source projects periodically, but project maintainers must opt in first. Each report includes a description of the potential vulnerability, a proof of concept showing how it can be exploited, and a suggested fix when available.
The key difference is that the reports are sent to maintainers without human review. Anthropic said that some project maintainers with the capacity to triage vulnerabilities at scale had requested all the findings discovered by the models, including unreviewed findings.
This approach shortens reporting times, but increases the possibility of errors, such as an incorrect assessment of severity. The company expects the rate of accurate findings to exceed 90%, with the aim of improving it over time. Projects that lack the capacity to handle the flow of findings will continue to receive disclosures verified by humans through Anthropic’s coordinated vulnerability disclosure process.
Operational Technology Security Program
The Critical Infrastructure Defense Program combines advanced Claude models, engineers working at customer sites, and Anthropic’s threat research for OT security providers relied upon by infrastructure operators.
The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. The group includes consulting and technology companies, cybersecurity vendors, and industrial equipment manufacturers responsible for building and patching systems.
Anthropic explained that OT systems often cannot be taken offline to apply patches, so known vulnerabilities may remain unaddressed for years. In rare cases, applying a patch safely may take decades. The company said some partners have already begun using Claude to address vulnerabilities and help their customers do so.
What Changes in Practice?
The two initiatives present different models for applying artificial intelligence to security: faster delivery of scan results to projects capable of triaging them, and more integrated collaboration with industrial systems security providers where remediation is constrained by operational continuity. However, the source provides no independent details about OSS Scanner’s performance or the mechanisms used to verify reports. The industrial program also begins with a small group of providers, with the aim of identifying the most effective and practical strategies before expanding to additional partners and sectors in the coming months.