→ Back to Home
DevSecOps

Anthropic Expands AI Cyber Capabilities for Vetted Security Teams, Addressing Critical Infrastructure and OSS Vulnerabilities

Anthropic has announced a significant expansion of its Cyber Verification Program (CVP), providing vetted security teams with broader access to its advanced AI models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with reduced cyber safeguards. This program is structured into three access tiers: defensive security work, authorized red teaming, and testing of systems critical to public safety or financial markets. The initiative, part of the broader "Anthropic Cyber Mission," aims to support defenders in securing critical infrastructure, such as power grids and water systems, and identifying vulnerabilities in open-source software (OSS). This development is critical for DevSecOps professionals and cybersecurity practitioners. As AI models become more sophisticated, their potential for both offensive and defensive cyber operations grows. The CVP allows legitimate security researchers and teams to harness these powerful AI capabilities for proactive threat detection, vulnerability assessment, and red-teaming exercises without being hampered by the conservative safeguards typically applied to general-purpose AI models. This directly addresses the increasing speed and sophistication of AI-driven cyberattacks, which are making traditional defense mechanisms less effective. The expansion of the CVP fits within a broader trend of leveraging AI to augment human capabilities in cybersecurity. The industry is witnessing a rapid adoption of AI in various security functions, from automated vulnerability discovery to incident response. However, this also introduces new challenges, such as the potential for AI agents to be misused or to inadvertently expose sensitive information, as seen in recent incidents involving AI coding agents. Anthropic's approach acknowledges this dual nature of AI by providing controlled access to its most potent models, ensuring they are used responsibly by trusted entities for defensive purposes. The company's previous Project Glasswing, which uncovered over 129,000 verified software vulnerabilities, underscores the effectiveness of AI in this domain. In practice, this means that security teams participating in the CVP will gain a significant advantage in identifying and mitigating complex vulnerabilities that might otherwise go undetected. For critical infrastructure operators, this could translate to enhanced resilience against state-sponsored attacks and other sophisticated threats. For the OSS community, the program, including the new OSS Scanner, offers free security scans from Anthropic's strongest models, potentially leading to a substantial reduction in the vast backlog of unpatched vulnerabilities. Practitioners should consider exploring participation in such programs if their organizations meet the vetting criteria, as it offers a unique opportunity to leverage frontier AI for advanced defensive strategies. It also highlights the growing need for clear governance and responsible AI development within the cybersecurity landscape, emphasizing that access to powerful AI tools must be carefully managed to prevent unintended consequences.
#ai security#critical infrastructure#open-source security#vulnerability management#red teaming#cyber verification program
Read original source