CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • Use Cases

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

Ask AI about aVenture

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
Anthropic launches critical infrastructure program and free OSS Scanner for open source

From SiliconANGLE

By Duncan Riley

October 8, 2026

Anthropic launches critical infrastructure program and free OSS Scanner for open source

Anthropic launches critical infrastructure program and free OSS Scanner for open source

Anthropic PBC today launched a program that brings its frontier models and onsite engineers to the security companies protecting power grids, water systems and other critical infrastructure.

OSS Scanner, launched with it, offers open-source projects free periodic vulnerability scans from the company’s strongest models. Both fall under a new effort Anthropic calls the Anthropic Cyber Mission.

The Critical Infrastructure Defense Program starts with the outside providers that operators of every size already rely on for advice on which fixes are safe to apply to a running system. Eleven of those providers signed on as founding partners.

Accenture plc, Booz Allen Hamilton Inc., Deloitte & Touche LLP and PricewaterhouseCoopers LLP come from the consulting side, where they run security programs for operators. Security vendors make up the biggest bloc, with industrial specialists Dragos Inc., Insane Cyber Inc. and Nozomi Networks Inc. joining CrowdStrike Holdings Inc. and Palo Alto Networks Inc. Hitachi Ltd. and Rockwell Automation Inc. build and patch the hardware itself.

The program is aimed at operational technology in plants, substations and water systems, where equipment built to run for decades often cannot be taken offline for a patch. Known flaws can sit there for years. Anthropic said several partners are already using Claude to fix vulnerabilities and to help their customers do the same. More partners and sectors are due to join over the coming months.

Andrew Turner, president of commercial cyber at Booz Allen, called operational technology “the next frontier for autonomous AI-enabled attacks” in comments published with the announcement. What matters now, he said, is how much control artificial intelligence can gain over an industrial process and how fast.

The announcement leaves out the commercial terms. Axios noted in its coverage that Anthropic has not said whether partners get free model access or who covers the computing costs. The same report questioned how partners will test and deploy fixes without disrupting utility operations.

The open-source half of today’s news grew out of a backlog in Anthropic’s own disclosure work. Of the more than 29,000 candidate vulnerabilities its models turned up in widely used software over the past six months, staff have manually reviewed about 6,000. A growing number of maintainers who received early reports asked for the whole unreviewed batch, proposed patches included, and nearly 5,000 such reports have gone out so far.

OSS Scanner turns that arrangement into a standing service for other eligible projects. Google LLC’s OSS-Fuzz, which runs fuzzers against open-source code, inspired the setup.

Every report includes a self-contained reproducer. Early tester Anton Arapov of the OpenSSL Corporation said a report with a real exploit attached is “basically job done for an engineer.” Where the model can manage it, a candidate patch comes with the write-up, and a bisection of the code history shows when the flaw was introduced.

Reports from the new service go straight to maintainers without human review so they arrive faster. Some will contain mistakes as a result, such as a wrong severity rating, Anthropic said.

To gauge how often that happens, Anthropic tested the scanner’s accuracy before opening it to more projects. The expert penetration testers who vet the company’s coordinated disclosures checked 97 critical and high-severity findings from an early version across 48 projects and cleared 85 for disclosure.

Of the other 12, all but one were real bugs that duplicated known issues or other findings from the scan. Embedded encryption library developer wolfSSL Inc. said all but two of the 74 reports it received during early trials were valid and that five became CVEs.

Core maintainers can enroll by submitting a pull request to an Anthropic GitHub repository. Eligibility follows the OSS-Fuzz test of “critical impact on infrastructure and user security,” with decisions made case by case. Projects without the staff to keep up with raw findings will still get human-verified reports through Anthropic’s existing disclosure process.

The Defender Advantage Fund that Anthropic set up in August pays to keep the scanner free. The company has also put money into the Python Software Foundation and the Apache Software Foundation, as well as Alpha-Omega and OpenSSF through the Linux Foundation.

Both launches draw on lessons from Project Glasswing. That program gave vetted organizations access to Claude Mythos from April until it was folded into an expanded Cyber Verification Program earlier this week. Finding vulnerabilities has never been easier, according to Anthropic. Verifying, prioritizing and fixing them remains hard, and the company said Glasswing has not yet cut cyber risk by enough.

Anthropic expects AI to favor defenders within two years. For now the cost of exploiting a flaw keeps falling, and verifying and repairing one is still slow work that depends on people. With operational technology, a fix may have to wait until it can go safely onto running machinery, and in rare cases that could take decades.

View original article on siliconangle.com

Most Recent

Jev creator TypeSafe closes $870M round at $7.5B valuation

TypeSafe Inc., the creator of the Jev artificial intelligence model, today announced that it has raised $870 million in funding at a $7.5 billion valuation. Andreessen Horowitz led the round with contributions from Sequoia Capital, DCVC and unnamed angel investors. The cash infusion comes less than

Oct 9, 2026

Seismora builds a control plane to route AI workloads across devices and clouds

Seismora is building a control plane to coordinate AI workloads across devices, edge infrastructure and multiple cloud providers.

Oct 9, 2026

Satellite radar tech startup Kapta Space raises $24M from Bill Gates-backed fund and defense investors

Kapta Space, a Seattle startup building lower-cost, steerable radar sensors for satellites, has raised $24 million in a Series A funding round to scale production and meet growing demand for defense intelligence contracts. The investment brings total funding to $30 million, following an initial $5 m

Oct 9, 2026

18 insights from SailPoint’s Navigate event: Enterprises race to bring identity security for AI agents up to machine speed

Identity security for AI agents is a board priority, and enterprises at Navigate 2026 are moving to just-in-time access and named human owners.

Oct 9, 2026

Similar Posts

Anthropic folds Project Glasswing into an expanded three-tier Cyber Verification Program

Anthropic PBC today expanded its Cyber Verification Program into three tiers of access for vetted security teams, with fewer blocks on cybersecurity work at each step up. The overhaul is aimed at a restriction Anthropic built into its own products. Because the company treats cybersecurity as dual-us

Oct 6, 2026

An opt-in vulnerability-finding service for open-source software

We’re launching OSS Scanner, an opt-in vulnerability scanner for the open-source ecosystem informed by our experience using Claude to find vulnerabilities during Project Glasswing. Projects that join will receive thorough, periodic security scans by our strongest models at no cost.

Oct 8, 2026

OpenAI, Anthropic and 100-plus firms warn AI attacks are about to explode

OpenAI Group PBC today published an open letter signed by more than 100 technology companies, banks, insurers and security vendors warning that artificial intelligence-enabled cyberattacks will become far more widespread within months and that defenders have a narrow period left to get ready. “We ha

Aug 27, 2026

CrowdStrike’s post-Mythos surge: Moat, momentum and the blast-radius test

CrowdStrike Holdings Inc.’s most recent earnings print shows that Anthropic PBC’s Mythos model transformed artificial intelligence security from something chief information security officers needed to worry about down the road into an immediate buying event. The company’s entrenched position in endp

Aug 29, 2026