Anthropic offers free Claude for scanning open-source vulnerabilities, over 29,000 suspected vulnerabilities already found
Beating AI News Flash: Anthropic launches the Anthropic Cyber Mission, a cybersecurity initiative, alongside the free vulnerability scanning service OSS Scanner and a critical infrastructure defense program. The former uses advanced models, including Claude Mythos, to regularly identify security vulnerabilities in eligible open-source software. The latter helps power grids, water plants, and transportation systems defend against cyberattacks.
Over the past 6 months, Anthropic used AI to discover more than 29,000 suspected vulnerabilities in open-source software, but only had time to manually review about 6,000. The new service allows project maintainers to directly receive reports that have not been manually reviewed. Each report includes a method to reproduce the vulnerability, an explanation of the issue, and remediation recommendations. Anthropic estimates that more than 90% are real vulnerabilities, but acknowledges that false positives may still occur.
The new service currently requires project maintainers to apply proactively, and is mainly aimed at important open-source projects capable of handling large volumes of vulnerability reports. Anthropic's previous testing involved projects such as PostgreSQL and OpenSSL. Among them, wolfSSL received 74 reports, 72 of which were valid, and 5 vulnerabilities received CVE numbers.
On the infrastructure side, Anthropic has partnered with 11 companies including CrowdStrike, Accenture, and Hitachi. The company will provide partners with Claude models, on-site engineers, and security research support to help them inspect and fix vulnerabilities for electricity, water, and transportation operators. These industrial systems are usually difficult to take offline for updates, and actual remediation still requires the involvement of professional personnel.