Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security
OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in.
Anthropic on Thursday announced two new cybersecurity initiatives: one gives open source maintainers faster access to AI-generated vulnerability reports, and the other targets companies that help secure operational technology (OT).
The programs build on lessons from Project Glasswing. Anthropic said Glasswing partners uncovered many vulnerabilities, but admitted that it has not yet cut cyber risk enough.
According to the company, finding vulnerabilities has never been easier, but verifying, prioritizing and patching them remains hard. Flaws found through Glasswing often took months to get fixed.
Scanner reports reach maintainers without human review
Inspired by Google’s OSS-Fuzz, OSS Scanner is a free service that uses Anthropic’s most capable models to periodically scan open source projects. Maintainers have to opt in to have their projects scanned.
Each report explains the potential vulnerability, includes a PoC showing how it could be exploited and, when one is available, suggests a fix.
Anthropic launched the service after some OSS maintainers who can triage vulnerabilities at scale asked for everything its AI models had found in their projects, including unreviewed findings.
“The reports are model-generated and sent without human review,” the AI giant said.
Skipping review gets reports to maintainers faster, but Anthropic warned that some will contain inaccuracies, such as wrong severity ratings. It expects a true-positive rate above 90% and aims to improve it over time.
The service is meant for projects with the capacity to keep up with the findings. Other projects will continue to receive human-verified disclosures through Anthropic’s coordinated vulnerability disclosure process.
Critical infrastructure program targets OT providers
The Critical Infrastructure Defense Program (CIDP) brings frontier Claude models, on-site engineers and Anthropic’s threat research to the providers that power, water, manufacturing and transportation operators rely on for OT security.
The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. They include consulting and technology firms, security vendors, and the manufacturers that build and patch industrial equipment.
Anthropic noted that OT systems often cannot be taken offline for patching, so known vulnerabilities can remain unresolved for years. In rare cases, it said, a patch could take decades to apply safely.
According to the company, several partners are already working with Claude to fix vulnerabilities and help customers do the same.
Anthropic is starting with a small group of providers to learn which strategies are most effective and practical. It plans to bring the program to more partners and sectors in the coming months.