Application Security

Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in.

Claude Mythos

Anthropic on Thursday announced two new cybersecurity initiatives: one gives open source maintainers faster access to AI-generated vulnerability reports, and the other targets companies that help secure operational technology (OT).

The programs build on lessons from Project Glasswing. Anthropic said Glasswing partners uncovered many vulnerabilities, but admitted that it has not yet cut cyber risk enough.

According to the company, finding vulnerabilities has never been easier, but verifying, prioritizing and patching them remains hard. Flaws found through Glasswing often took months to get fixed.

Scanner reports reach maintainers without human review 

Inspired by Google’s OSS-Fuzz, OSS Scanner is a free service that uses Anthropic’s most capable models to periodically scan open source projects. Maintainers have to opt in to have their projects scanned.

Each report explains the potential vulnerability, includes a PoC showing how it could be exploited and, when one is available, suggests a fix.

Anthropic launched the service after some OSS maintainers who can triage vulnerabilities at scale asked for everything its AI models had found in their projects, including unreviewed findings.

Advertisement. Scroll to continue reading.

“The reports are model-generated and sent without human review,” the AI giant said.

Skipping review gets reports to maintainers faster, but Anthropic warned that some will contain inaccuracies, such as wrong severity ratings. It expects a true-positive rate above 90% and aims to improve it over time.

The service is meant for projects with the capacity to keep up with the findings. Other projects will continue to receive human-verified disclosures through Anthropic’s coordinated vulnerability disclosure process.

Critical infrastructure program targets OT providers

The Critical Infrastructure Defense Program (CIDP) brings frontier Claude models, on-site engineers and Anthropic’s threat research to the providers that power, water, manufacturing and transportation operators rely on for OT security.

The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. They include consulting and technology firms, security vendors, and the manufacturers that build and patch industrial equipment.

Anthropic noted that OT systems often cannot be taken offline for patching, so known vulnerabilities can remain unresolved for years. In rare cases, it said, a patch could take decades to apply safely.

According to the company, several partners are already working with Claude to fix vulnerabilities and help customers do the same.

Anthropic is starting with a small group of providers to learn which strategies are most effective and practical. It plans to bring the program to more partners and sectors in the coming months.

Related: Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

Related: Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Related: Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

Related Content

Artificial Intelligence

Researchers from George Washington University have published a paper examining whether the time and cause of AI going rogue can be predicted.

Artificial Intelligence

The cybersecurity startup will invest in product innovation, agentic research, and employee base expansion.

Artificial Intelligence

Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.

Artificial Intelligence

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations

Artificial Intelligence

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

Artificial Intelligence

The announcement comes after Trump hosted top executives of AI companies at the White House last week.

Cybersecurity Funding

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority.

Artificial Intelligence

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version