Security News

Anthropic Launches Program to Help Secure Critical Infrastructure and Open Source Software

CyberScoop · 9 Oct 2026
Key Takeaway If your business relies on open-source software, keep it up to date and be ready to apply patches promptly, while checking any automated vulnerability findings before acting on them.

Anthropic has announced a new program, described as a "long-term commitment" to cybersecurity, that combines its Claude AI models, engineers and threat research with the expertise of outside security companies. Partners named include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. The aim is to find and repair weaknesses in critical infrastructure and open-source software before they can be misused.

Anthropic said defenders in these areas have decades of experience but face severe resource shortages. It says it has already offered frontier models and technical support to more than half the states in the U.S., as well as large critical infrastructure operators, to scan and patch code or help with incident response and red teaming. The company acknowledged that critical infrastructure is hard to defend in ways AI cannot fix, and said it will start with a small group of providers to learn which strategies work best.

For open-source software, Anthropic is creating an opt-in scanning service offering free, periodic scans of projects, with a proof of concept, an explanation and suggested patching options. This followed requests from some maintainers for everything the model had found, even unreviewed findings. Anthropic noted that reports will arrive faster but may contain inaccuracies. Its long-term goal is to automate most triage and patching and to develop new security architectures and coding standards.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from CyberScoop, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.