AI company moves to defend critical infrastructure and open-source projects from AI
Anthropic has launched an effort to help people patch the software vulnerabilities exposed by its own Project Glasswing.
If that sounds like a careless camper starting a wildfire and later funding a fire department, well, that's one way of looking at it.
Anthropic insists it wants to give defenders access to the tools attackers are already using.
Under a program name that sounds like a forthcoming Tom Cruise film – "Anthropic Cyber Mission" – the Claudefather is directing its effort into two areas.
The first is a Critical Infrastructure Defense Program, because no one wants AI models showing miscreants how to shut down public utilities with newly discovered zero-day SCADA vulnerabilities.
The program combines the company's priciest models with on-site engineers – sometimes now referred to as forward deployed engineers – because despite the sophistication of AI coding agents, human security experts are still useful and many organizations lack in-house talent tutored in the ways of machine learning.
Anthropic aims to tackle this challenge with the help of a stable of partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
These organizations have ties to critical infrastructure organizations and are already working to safeguard the fragile technical framework being probed constantly by AI agents.
The second area of focus for the Anthropic Cyber Mission involves a service called OSS Scanner, "which offers open-source projects regular security scans from our strongest models, for free." The offer does not extend to all open-source projects, nor is it entirely free.
Anthropic has borrowed the eligibility criteria used by Google for its OS-FUZZ project and will therefore work on "established projects that have a critical impact on infrastructure and user security." So if you just have a public web app repo languishing on GitHub, you can instead turn to existing tools like Socket, Dependabot, OSV-Scanner, Trivy, Renovate, or something similar.
And maybe you'll be able to get your AI coding agent of choice to audit your site without balking when faced with a security audit.
But for those involved in influential and widely used open-source projects, reinforcements are at hand, so long as project maintainers don't mind having their "materials" – inputs and outputs – used for model training, per the consumer terms of service Anthropic applied to OSS Scanner.
Really though, most established open-source projects have already been captured in training data sets.
Projects allowed to enroll can expect periodic automated scans that provide details about how identified bugs may be exploitable.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.