[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTsOlM370_kuTGwqj70tC4PNhU9mJcby5CCyc1IHRJUg":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"a5106749-438c-4712-be3f-070b2c4cf596","Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security","anthropic-fast-tracks-ai-bug-reports-to-oss-maintainers-taps-11-firms-for-ot-sec-dada16","OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in. The post Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security appeared first on SecurityWeek.","Anthropic has launched two new cybersecurity initiatives. The first, OSS Scanner, uses AI to scan open source projects for vulnerabilities and sends unreviewed reports directly to opt-in maintainers for faster patching. The second, the Critical Infrastructure Defense Program (CIDP), leverages Anthropic's AI models and threat research to assist OT security providers in securing critical infrastructure.","Anthropic launches AI-powered OSS vulnerability scanning and OT security programs.","Anthropic on Thursday announced two new cybersecurity initiatives: one gives open source maintainers faster access to AI-generated vulnerability reports, and the other targets companies that help secure operational technology (OT). The programs build on lessons from Project Glasswing. Anthropic said Glasswing partners uncovered many vulnerabilities, but admitted that it has not yet cut cyber risk enough. According to the company, finding vulnerabilities has never been easier, but verifying, prioritizing and patching them remains hard. Flaws found through Glasswing often took months to get fixed. Scanner reports reach maintainers without human review Inspired by Google’s OSS-Fuzz, OSS Scanner is a free service that uses Anthropic’s most capable models to periodically scan open source projects. Maintainers have to opt in to have their projects scanned. Each report explains the potential vulnerability, includes a PoC showing how it could be exploited and, when one is available, suggests a fix. Anthropic launched the service after some OSS maintainers who can triage vulnerabilities at scale asked for everything its AI models had found in their projects, including unreviewed findings.Advertisement. Scroll to continue reading. “The reports are model-generated and sent without human review,” the AI giant said. Skipping review gets reports to maintainers faster, but Anthropic warned that some will contain inaccuracies, such as wrong severity ratings. It expects a true-positive rate above 90% and aims to improve it over time. The service is meant for projects with the capacity to keep up with the findings. Other projects will continue to receive human-verified disclosures through Anthropic’s coordinated vulnerability disclosure process. Critical infrastructure program targets OT providers The Critical Infrastructure Defense Program (CIDP) brings frontier Claude models, on-site engineers and Anthropic’s threat research to the providers that power, water, manufacturing and transportation operators rely on for OT security. The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. They include consulting and technology firms, security vendors, and the manufacturers that build and patch industrial equipment. Anthropic noted that OT systems often cannot be taken offline for patching, so known vulnerabilities can remain unresolved for years. In rare cases, it said, a patch could take decades to apply safely. According to the company, several partners are already working with Claude to fix vulnerabilities and help customers do the same. Anthropic is starting with a small group of providers to learn which strategies are most effective and practical. It plans to bring the program to more partners and sectors in the coming months. Related: Anthropic Introduces 3-Tier Cyber Verification Program for AI Access Related: Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up Related: Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router FlawsOracle Health Data Breach Tally Climbs to Nearly 20 MillionGeorgia Power, Alabama Power Data Breach Hits 400,000 AccountsAdvantest Discloses Data Breach Months After Ransomware AttackAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesFBI Blames Contractor’s Missed Patch for ShinyHunters BreachCybersecurity M&A Roundup: 39 Deals Announced in September 2026 Latest News Citrix Urges Immediate Patching of Critical NetScaler VulnerabilityGoogle Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnFormula Predicts When AI Chatbots Are at Risk of Turning BadCisco Patches a Dozen Critical VulnerabilitiesSecurity Awareness Training Isn’t Dead, but It Needs a RethinkAttackers Target Critical Atlassian Vulnerability Within Hours of PoC PublicationUS Seeks Alleged Chinese Hafnium Hacker With $10 Million RewardSonicWall and Splunk Patch Critical Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fanthropic-fast-tracks-ai-bug-reports-to-oss-maintainers-taps-11-firms-for-ot-security\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F05\u002FClaude-Mythos.jpeg","2026-10-09T08:19:33+00:00","2026-10-09T10:00:27.693707+00:00",7,[18,21,23,25,28,30],{"name":19,"type":20},"Claude","product",{"name":22,"type":20},"OSS Scanner",{"name":24,"type":20},"Project Glasswing",{"name":26,"type":27},"Anthropic","vendor",{"name":29,"type":27},"Google",{"name":31,"type":27},"Accenture","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":54},{"id":32,"icon":34,"name":35,"slug":36},[]]