Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security
Anthropic launched unreviewed AI vulnerability reports for OSS maintainers and an OT security program with 11 firms.
Anthropic announced OSS Scanner, a free service that uses its strongest models to periodically scan opted-in open source projects and email maintainers model-generated vulnerability reports without human review. Each report describes the flaw, includes a proof of concept, and suggests a fix when one is available; Anthropic expects a true-positive rate above 90 percent but warns some findings will be inaccurate. Separately, the Critical Infrastructure Defense Program gives frontier Claude models, on-site engineers, and threat research to 11 founding partners that secure operational technology for power, water, manufacturing, and transportation. Anthropic said Glasswing findings often took months to patch and that some OT fixes can take years because systems cannot be taken offline.
- OSS Scanner sends unreviewed AI vulnerability reports, PoCs, and suggested fixes to opted-in maintainers.
- Anthropic expects a true-positive rate above 90 percent but warns some severity ratings will be wrong.
- Projects that cannot triage at scale still get human-verified disclosures.
- CIDP pairs Claude and on-site engineers with 11 OT security and industrial partners.
- OT flaws can stay unpatched for years because systems often cannot be taken offline.
Full article460 words · extracted from securityweek.com · click to collapse
Anthropic on Thursday announced two new cybersecurity initiatives: one gives open source maintainers faster access to AI-generated vulnerability reports, and the other targets companies that help secure operational technology (OT).
The programs build on lessons from Project Glasswing. Anthropic said Glasswing partners uncovered many vulnerabilities, but admitted that it has not yet cut cyber risk enough.
According to the company, finding vulnerabilities has never been easier, but verifying, prioritizing and patching them remains hard. Flaws found through Glasswing often took months to get fixed.
Scanner reports reach maintainers without human review
Inspired by Google’s OSS-Fuzz, OSS Scanner is a free service that uses Anthropic’s most capable models to periodically scan open source projects. Maintainers have to opt in to have their projects scanned.
Each report explains the potential vulnerability, includes a PoC showing how it could be exploited and, when one is available, suggests a fix.
Anthropic launched the service after some OSS maintainers who can triage vulnerabilities at scale asked for everything its AI models had found in their projects, including unreviewed findings.
Advertisement. Scroll to continue reading.
“The reports are model-generated and sent without human review,” the AI giant said.
Skipping review gets reports to maintainers faster, but Anthropic warned that some will contain inaccuracies, such as wrong severity ratings. It expects a true-positive rate above 90% and aims to improve it over time.
The service is meant for projects with the capacity to keep up with the findings. Other projects will continue to receive human-verified disclosures through Anthropic’s coordinated vulnerability disclosure process.
Critical infrastructure program targets OT providers
The Critical Infrastructure Defense Program (CIDP) brings frontier Claude models, on-site engineers and Anthropic’s threat research to the providers that power, water, manufacturing and transportation operators rely on for OT security.
The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. They include consulting and technology firms, security vendors, and the manufacturers that build and patch industrial equipment.
Anthropic noted that OT systems often cannot be taken offline for patching, so known vulnerabilities can remain unresolved for years. In rare cases, it said, a patch could take decades to apply safely.
According to the company, several partners are already working with Claude to fix vulnerabilities and help customers do the same.
Anthropic is starting with a small group of providers to learn which strategies are most effective and practical. It plans to bring the program to more partners and sectors in the coming months.
Related: Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
Related: Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Related: Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion