Anthropic has introduced Anthropic Cyber Mission, a cybersecurity initiative that includes a free vulnerability scanning service called OSS Scanner and a separate defense program for critical infrastructure. The company said its AI systems, including Claude Mythos, identified more than 29,000 suspected vulnerabilities in open-source software over the past six months, though only about 6,000 of those findings were manually reviewed. Under the new service, eligible open-source maintainers can receive reports directly even before human verification. Each report includes reproduction steps, an explanation of the issue, and suggested fixes. Anthropic said it expects more than 90% of the findings to be real vulnerabilities, while acknowledging that false positives can still occur. The company said the service is currently available by application and is aimed mainly at important open-source projects that can handle a large volume of reports. Anthropic also said earlier testing covered projects such as PostgreSQL and OpenSSL. In one example, 72 of 74 reports sent to wolfSSL were valid, and five vulnerabilities received CVE identifiers. For critical infrastructure, Anthropic said it is working with 11 companies including CrowdStrike, Accenture, and Hitachi.
Anthropic has rolled out Anthropic Cyber Mission, a cybersecurity program that includes a free open-source vulnerability scanning service called OSS Scanner and a separate effort focused on defending critical infrastructure.
OSS Scanner uses advanced models, including Claude Mythos, to regularly search eligible open-source software for security flaws. Anthropic said its AI systems found more than 29,000 suspected vulnerabilities in open-source software over the past six months, but only about 6,000 were manually reviewed. The new service lets project maintainers receive reports directly without prior human review. Each report includes steps to reproduce the issue, an explanation of the problem, and recommendations for fixing it. Anthropic said it expects more than 90% of the findings to be real vulnerabilities, while noting that false positives remain possible.
The service currently requires maintainers to apply and is aimed mainly at important open-source projects that can handle a large number of vulnerability reports. Anthropic said earlier testing involved projects including PostgreSQL and OpenSSL. In one case, wolfSSL received 74 reports, 72 of which were valid, and five vulnerabilities were assigned CVE identifiers.
On the critical infrastructure side, Anthropic said it has joined with 11 companies, including CrowdStrike, Accenture, and Hitachi. The company will provide Claude models, on-site engineers, and security research support to help partners inspect and fix vulnerabilities for power, water, and transportation operators. Anthropic added that these industrial systems are often difficult to take offline for updates, so actual remediation still requires specialist involvement.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.