Anthropic and Nozomi bring AI vulnerability research to OT security

Share This Post

Nozomi Networks has joined Anthropic’s Project Glasswing, an initiative using artificial intelligence to identify software vulnerabilities in critical infrastructure and connected systems.

The company will contribute expertise in operational technology, the Internet of Things, and cyber-physical systems. It plans to apply advanced AI models to vulnerability discovery within its platform, contribute findings to Anthropic’s research, and share relevant results with the wider cybersecurity community.

Project Glasswing brings together software companies, infrastructure providers, and security specialists. Participating organisations receive access to Claude Mythos Preview to examine software for vulnerabilities and assess how frontier AI models perform against critical systems.

Anthropic said organisations involved in the project have used the model to scan their codebases. The company reported that Claude Mythos Preview had identified more than 10,000 potential findings rated by the model as high or critical severity across participating organisations’ codebases.

Anthropic has also used an earlier version of Claude Mythos Preview to examine open-source software. External security researchers helped triage and validate the results before reviewed findings were disclosed to software maintainers.

Nozomi’s involvement extends that research into software designed for industrial and connected-device environments. These environments can link enterprise applications, remote-access services, cloud platforms, sensors, controllers, and physical equipment.

Those connections allow data and access to move between IT and OT systems. They also require security teams to consider the operational role of affected assets, as vulnerabilities connected to production environments must be assessed against performance, reliability, and safety requirements.

Operational context shapes vulnerability priorities

OT environments often include equipment with long operating lifecycles, limited maintenance windows, and systems that cannot be patched using the same processes as office software. Cyber incidents can also affect physical equipment, production processes, and safety systems.

NIST defines OT as programmable systems and devices that interact with the physical environment or manage devices that do so. Its guidance says OT cybersecurity controls must account for performance, reliability, and safety.

A technical severity rating therefore provides only part of the information needed to prioritise an OT vulnerability. Operators must also consider where the affected software is deployed, which process it supports, how it is connected, and what would happen if the asset failed or were taken offline.

Operational priority also depends on the affected asset’s function, including whether it supports monitoring, production control, or a safety-related process.

CISA guidance similarly links vulnerability management with asset visibility and categorisation. Organisations need to identify the systems and functions affected before deciding which findings require immediate action.

Project Glasswing’s reported volume of model-generated findings places additional importance on human validation and operational prioritisation. Nozomi and Anthropic have not disclosed how false positives will be measured or how process-level risk will be assigned to model-generated results.

Nozomi already uses AI and machine learning in its platform to analyse industrial network communications, process variables, assets, and network relationships. The company specialises in cybersecurity for OT, IoT, and critical infrastructure environments.

Nozomi said it will use Project Glasswing’s models within its own platform. The available information does not indicate that the project will involve direct testing of live customer equipment or production networks.

Nozomi is not the first industrial cybersecurity company to join the initiative. Dragos joined Project Glasswing the previous month and is using Claude Mythos Preview to examine its own products for previously unidentified vulnerabilities.

Dragos said the work would help protect its software and provide information on how frontier AI models perform against products used in OT environments. The company plans to share its findings with the wider security community.

The work disclosed by both companies is centred on vendor-controlled software. Testing source code or products in a controlled environment presents different operational risks from scanning equipment inside an operating factory, utility, or transport system.

Testing without disrupting operations

NIST advises organisations to assess how vulnerability-scanning tools could affect OT components and communications. Its guidance recommends evaluating scanning tools in an offline environment before introducing them into production.

Active testing can generate traffic and queries that affect timing-sensitive or resource-constrained OT components. An interrupted connection or unstable device can affect a physical process when the component supports production, control, or safety functions.

Replicated, virtualised, or simulated systems provide alternatives for evaluating testing methods without immediately exposing production equipment. Where live testing is necessary, it may need to take place during a planned outage or maintenance period.

These controls are relevant to AI-assisted vulnerability research because identifying a weakness and testing an operating system are separate activities. A model can analyse software without determining how an operator should examine or modify the affected equipment.

Discovery and remediation are also separate stages. Finding a vulnerability does not establish whether an operator can install a patch immediately, particularly when equipment must remain available or an update requires testing against specialised hardware.

NIST describes patch management as a process that includes identifying, prioritising, acquiring, installing, and verifying updates. OT operators must carry out those steps while accounting for system availability and safety.

An operator may need to test a vendor update, schedule its installation, and confirm that the change has not affected the industrial process. Where immediate patching is not possible, operators can evaluate compensating controls based on the affected system and its operational requirements.

Project Glasswing is examining how AI developers, software providers, infrastructure operators, and security specialists can use advanced models for defensive vulnerability research. Anthropic has positioned the initiative around identifying and addressing weaknesses in critical software.

Nozomi will contribute OT, IoT, and cyber-physical systems expertise while applying the models within its platform. The company said it will also contribute research insights to Anthropic and share relevant findings with the broader cybersecurity community.

(Photo by MARCO)

See also: NVIDIA T3000 and T2000 target robotics cost and power limits

Banner for IoT Tech Expo by TechEx events.

Want to learn more about the IoT from industry leaders? Check out IoT Tech Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including AI & Big Data Expo and the Cyber Security Expo. Click here for more information.

IoT News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Adblock test (Why?)

More To Explore

  • About
  • Smart Tech
  • Solutions
  • Join Us
  • Contact
  • Contractor’s Hub