Business

Anthropic Deploys Claude to Hunt Bugs in Critical Systems

Anthropic has launched its Cyber Mission initiative, deploying Claude models to automatically detect security vulnerabilities in open-source software and critical physical infrastructure.

AlphaSignal17 hrs agoBusiness
Image: AlphaSignal

Anthropic's new Cyber Mission unites two distinct defensive initiatives. The Critical Infrastructure Defense Program partners with major security providers—including CrowdStrike, Palo Alto Networks, Dragos, Rockwell Automation, Accenture, Deloitte, PwC, Booz Allen, Hitachi, Insane Cyber, and Nozomi Networks—to protect operational technology like power grids and water systems. Meanwhile, the OSS Scanner program provides free, automated vulnerability reports to high-impact open-source projects, including PostgreSQL, OpenSSL, wolfSSL, and HotCRP, using Anthropic's Claude Mythos model.

The OSS Scanner reviews source code and delivers reports directly to maintainers without human triage. These reports include a vulnerability explanation, a proof-of-concept exploit, a candidate patch, and a version-history bisection. Anthropic targets a true-positive rate above 90% for these automated findings. In early tests of 97 critical and high-severity reports across 48 projects, expert penetration testers found that 85 reports, or 88%, qualified for formal disclosure, and 96 of the 97 corresponded to real vulnerabilities. For example, wolfSSL reported that 72 of 74 received findings were valid, with five receiving CVE identifiers.

This automated approach addresses a massive bottleneck in human triage. Anthropic's previous Project Glasswing identified over 29,000 candidate vulnerabilities in six months, but human reviewers could only manually assess 6,000 of them. Rapidly improving model capabilities have exacerbated this gap; on the CyberGym academic vulnerability-finding benchmark, large language models improved their detection rate from below 20% to above 85% in roughly a year.

For security practitioners and open-source maintainers, this initiative shifts the operational burden. While Claude can generate exploits and patches in minutes, human developers must still verify exploitability, test for regressions, and coordinate deployments. In operational technology environments, where patches must wait for scheduled maintenance windows, remediation can take months or even years. Anthropic's programs aim to give defenders an early warning, but practitioners must now adapt to a high volume of raw, model-generated reports.

This is our own summary of reporting by AlphaSignal

More in Business