Anthropic and OpenAI are now partners in a program designed to defend power grids, factories, and hospitals from the vulnerability flood their own models help create. Palo Alto Networks launched the Frontier AI Critical Defense Program on August 19 with the two labs, plus Mitsubishi Electric, Axis Communications, Health-ISAC, the Analysis and Resilience Center for Systemic Risk, EPRI, and Linux Foundation initiative Akrites.
The urgency comes from Unit 42’s own numbers. During a two-month run, the unit’s NOVA system counted 14,090 confirmed flaws. The tool swept 3,915 open-source projects, and 99.4 percent of its findings had never been reported before. Nearly 40 percent rated high or critical. Infrastructure operators bound by uptime and safety rules cannot patch at that pace.
The program’s answer is virtual patching: firewall and SASE protections that block exploit traffic before it reaches a vulnerable system, deployed through the company’s Advanced Threat Prevention service. Members share sensitive flaw details inside an embargoed network, and vendors get anonymized telemetry showing how their code is being attacked in the wild. Palo Alto says the model shrinks the industry’s average 55-day patch window toward zero exposure.
The effort extends Project Lightwell with IBM and Red Hat, and Microsoft’s participation via MAPP.