Anthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source software
Anthropic launched a program pairing Claude with security firms to find and fix flaws in critical infrastructure and open-source software.
Anthropic announced a critical-infrastructure defense program that combines Claude models, its engineers, and threat research with outside cybersecurity companies. Named partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Anthropic said it has already offered frontier models to more than half of U.S. states and large operators for code scanning, patching, incident response, and red teaming. It also launched an opt-in service giving open-source maintainers free periodic scans with proofs of concept, explanations, and suggested patches, while warning that faster reports may contain inaccuracies.
- Program pairs Claude with eleven cybersecurity and industrial partners.
- Anthropic says it already supports more than half of U.S. states.
- Opt-in service offers free periodic open-source scans and suggested patches.
- Faster reports may include unreviewed or inaccurate findings.
- Long-term goal is automated triage, patching, and new architectures.
Full article735 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The critical infrastructure defense program will seek to pair Claude models, Anthropic engineers and threat research with the expertise of cybersecurity companies.
Listen to this article
0:00
Learn more.
Anthropic announced a new program Thursday that will combine its AI tools with outside cybersecurity companies to find and fix cybersecurity vulnerabilities in critical infrastructure and open-source software.
Advertised as part of a new, “long-term commitment” to cybersecurity, the critical infrastructure defense program will pair Claude models, Anthropic engineers and threat research with the expertise of cybersecurity companies, including Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
“Defenders of critical infrastructure and the [open-source software] community have decades of security experience but have faced severe resource shortages that are exacerbated by this moment,” Anthropic wrote in a blog post. “We are recognizing their expertise in these domains and offering our support.”
Anthropic said it has offered frontier models and technical support to more than half the states in the U.S., as well as large operators of critical infrastructure to scan and patch code or assist in incident response and red teaming activities.
“Critical infrastructure is hard to defend in many ways that AI cannot fix, but we believe that frontier models can help find and repair weaknesses before those weaknesses are used to cut off power or make water unsafe, the company wrote. “Our first step is to work with a small cohort of providers to learn which strategies are most effective and practical.”
The company said it has engaged in similar work with maintainers of large open-source software projects, and some organizations asked for everything the model had found in their software, even unreviewed findings.
That spurred Anthropic to create a new opt-in scanning service for open source software, where organizations can get free, periodic scans of their projects with a proof of concept, explanation and suggested patching options. Anthropic noted that under this program, organizations will receive their reports faster but they may contain inaccuracies.
The long-term goal is to automate most triage and patching and develop new security architectures and coding standards.
As AI models have developed increasingly powerful cybersecurity capabilities, such as finding and exploiting known vulnerabilities, frontier AI companies have worried that bad actors could gain access to the tools faster than legitimate organizations. Anthropic and OpenAI have since both started programs funneling their tech to businesses and governments, free of charge, for defensive cybersecurity.
More Scoops
The US needs a real plan to defend its water systems
Here’s what it would take: stronger defenses for large utilities, hands-on help for smaller systems and federal support to make both happen.
The legal questions raised by agentic AI hacks
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Latest Podcasts
Government
Major rules for federal contractors handling sensitive data are nearing the finish line
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
Former NSA chief Nakasone says agency overhaul is ‘probably needed’
Here’s how experts think CISA should tell agencies to protect OT
Technology
Threats
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
Citrix discloses third actively exploited NetScaler zero-day in less than a week
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
AI policy circles targeted in China-linked phishing operation