Application Security
Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security
OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in.

By
|
October 9, 2026 (4:19 AM ET)
- + Flipboard + Reddit [+ Whatsapp](https://web.whatsapp.com/send?text=Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security https://www.securityweek.com/anthropic-fast-tracks-ai-bug-reports-to-oss-maintainers-taps-11-firms-for-ot-security/) [+ Whatsapp](whatsapp://send?text=Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security https://www.securityweek.com/anthropic-fast-tracks-ai-bug-reports-to-oss-maintainers-taps-11-firms-for-ot-security/) + Email

Anthropic on Thursday announced two new cybersecurity initiatives: one gives open source maintainers faster access to AI-generated vulnerability reports, and the other targets companies that help secure operational technology (OT).
The programs build on lessons from Project Glasswing. Anthropic said Glasswing partners uncovered many vulnerabilities, but admitted that it has not yet cut cyber risk enough.
According to the company, finding vulnerabilities has never been easier, but verifying, prioritizing and patching them remains hard. Flaws found through Glasswing often took months to get fixed.
Scanner reports reach maintainers without human review
Inspired by Google’s OSS-Fuzz, OSS Scanner is a free service that uses Anthropic’s most capable models to periodically scan open source projects. Maintainers have to opt in to have their projects scanned.
Each report explains the potential vulnerability, includes a PoC showing how it could be exploited and, when one is available, suggests a fix.
Anthropic launched the service after some OSS maintainers who can triage vulnerabilities at scale asked for everything its AI models had found in their projects, including unreviewed findings.
Advertisement. Scroll to continue reading.
“The reports are model-generated and sent without human review,” the AI giant said .
Skipping review gets reports to maintainers faster, but Anthropic warned that some will contain inaccuracies, such as wrong severity ratings. It expects a true-positive rate above 90% and aims to improve it over time.
The service is meant for projects with the capacity to keep up with the findings. Other projects will continue to receive human-verified disclosures through Anthropic’s coordinated vulnerability disclosure process.
Critical infrastructure program targets OT providers
The Critical Infrastructure Defense Program (CIDP) brings frontier Claude models, on-site engineers and Anthropic’s threat research to the providers that power, water, manufacturing and transportation operators rely on for OT security.
The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. They include consulting and technology firms, security vendors, and the manufacturers that build and patch industrial equipment.
Anthropic noted that OT systems often cannot be taken offline for patching, so known vulnerabilities can remain unresolved for years. In rare cases, it said, a patch could take decades to apply safely.
According to the company, several partners are already working with Claude to fix vulnerabilities and help customers do the same.
Anthropic is starting with a small group of providers to learn which strategies are most effective and practical. It plans to bring the program to more partners and sectors in the coming months.
Related : Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
Related : Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Related : Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

Written By
Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
More from Eduard Kovacs
- Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
- US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward
- TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
- Oracle Health Data Breach Tally Climbs to Nearly 20 Million
- Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
- Advantest Discloses Data Breach Months After Ransomware Attack
- Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
- Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies
Latest News
- OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks
- In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
- Google Domains Impacted by Recent ccTLD Hijacks
- Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
- Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
- US Disrupts Chinese State-Sponsored Hacking Tools
- Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
- Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

Trending
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
## Webinar: AI Is Accelerating Risk. Can Your IT Operations Keep Up?
October 14, 2026
Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline.
## Virtual Event: Zero Trust & Identity Strategies Summit 2026
October 14, 2026
Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.
People on the Move
Rapid7 has named Rik Ferguson as VP of Security Intelligence.
Cytactic has appointed Tim Brown as CSO.
Scott Simkin has joined Vega as CMO.
Expert Insights
## AI Has Changed Attack Speed, Not Security Fundamentals

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb)
## Four Cyber Threats Harboring Big Plans for the Future

- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin)
## Begin at the End: How to Enable Agentic Remediation

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael)
## “We Think the Security Control Is Working” Is No Longer Good Enough

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar)
## This Key Will Self-Destruct: An Open Standard for Revocable API Keys

Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. (Matt Honea)
- + Flipboard + Reddit [+ Whatsapp](https://web.whatsapp.com/send?text=Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security https://www.securityweek.com/anthropic-fast-tracks-ai-bug-reports-to-oss-maintainers-taps-11-firms-for-ot-security/) [+ Whatsapp](whatsapp://send?text=Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security https://www.securityweek.com/anthropic-fast-tracks-ai-bug-reports-to-oss-maintainers-taps-11-firms-for-ot-security/) + Email
Popular Topics
Security Community
- Virtual Cybersecurity Events
- Webcast Library
- CISO Forum
- AI Risk Summit
- ICS Cybersecurity Conference
- Cybersecurity Newsletters
Stay Intouch
About SecurityWeek
News Tips
Got a confidential news tip? We want to hear from you.
Advertising
Reach a large audience of enterprise cybersecurity professionals
Daily Briefing Newsletter
Subscribe to the SecurityWeek Daily Briefing and get the latest content delivered to your inbox.
Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.
