Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

Anthropic’s AI-Driven Cybersecurity Push: Faster Bug Reports and OT Security Boost

In a significant move to bolster cybersecurity, Anthropic has launched two initiatives that demonstrate the company’s commitment to using artificial intelligence (AI) to protect against vulnerabilities. The first program, called OSS Scanner, uses Anthropic’s most advanced models to rapidly scan open-source projects for potential security flaws, while the second initiative targets companies that help secure operational technology (OT).

The inspiration behind these efforts comes from Project Glasswing, a previous collaborative effort between Anthropic and its partners. During this project, vulnerabilities were uncovered at an unprecedented rate, but sadly, many of them took months to be patched. This experience has led Anthropic to acknowledge the limitations of current vulnerability disclosure processes.

OSS Scanner is a free service that uses AI models to periodically scan open-source projects. Maintainers can opt-in to have their projects scanned, and each report generated by the system explains potential vulnerabilities, includes a proof-of-concept (PoC) demonstrating how it could be exploited, and suggests a fix when available. The key innovation here is that these reports are model-generated and sent without human review, allowing maintainers to receive them faster.

However, Anthropic warns that some of these reports may contain inaccuracies, such as incorrect severity ratings. The company expects a true-positive rate above 90% and aims to improve this over time. It’s worth noting that this service is intended for projects with the capacity to handle high volumes of findings; other projects will continue to receive human-verified disclosures through Anthropic’s coordinated vulnerability disclosure process.

The second initiative, Critical Infrastructure Defense Program (CIDP), brings together top consulting firms and security vendors to provide OT security support to critical infrastructure providers. These partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.

The CIDP aims to address the unique challenges of securing OT systems, which often cannot be taken offline for patching. As a result, known vulnerabilities can remain unresolved for years – in some cases, even decades. Anthropic is starting with a small group of providers to learn which strategies are most effective and practical before expanding the program.

These initiatives demonstrate Anthropic’s commitment to harnessing AI for cybersecurity purposes. While there are potential risks associated with relying on model-generated reports, the benefits of faster vulnerability disclosure and improved OT security are undeniable. As we move forward in an increasingly complex digital landscape, collaboration between companies like Anthropic and experts from various fields will be crucial in mitigating emerging threats.

In practice, this means that users of open-source projects can now receive AI-generated vulnerability reports faster, but also need to remain vigilant about potential inaccuracies. For OT providers, partnering with companies like those involved in the CIDP can help bridge the gap between security measures and actual implementation.


Source: SecurityWeek — 2026-10-09