ANTHROPIC has announced two cybersecurity programmes, building on Project Glasswing. The company said the initiative uncovered many vulnerabilities, but flaws often took months to fix because verification, prioritisation and patching remain difficult. Its free OSS Scanner will periodically scan open-source projects whose maintainers opt in, using Anthropic’s most capable AI models. Reports describe potential vulnerabilities, include a proof of concept and suggest a fix where available.
They are sent without human review, so may contain errors, including incorrect severity ratings. Anthropic expects a true-positive rate above 90% and says it will work to improve this. Projects unable to handle the unreviewed reports will continue to receive human-verified disclosures through its coordinated vulnerability disclosure process.
The second programme, the Critical Infrastructure Defense Program (CIDP), will provide frontier Claude models, on-site engineers and threat research to companies that help secure operational technology used by power, water, manufacturing and transport operators. Its 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
Anthropic said OT systems can be difficult to take offline for patching, leaving known vulnerabilities unresolved for years; in rare cases, it said, applying a patch safely could take decades. Several partners are already using Claude to address vulnerabilities and assist customers. Anthropic is starting with a small group to assess what works in practice, and plans to expand the programme to more partners and sectors in the coming months.