了解 Wiz、Palo Alto Networks 和 Accenture 等公司如何利用 Claude Opus 更快地发现和修复漏洞,并大规模部署 AI 防御体系。
- 分类企业 AI
- 产品Claude 安全Claude 平台
- 日期2026 年 5 月 21 日
- 阅读时间5分钟
- https://claude.com/blog/how-our-partners-are-putting-opus-to-work-for-cybersecurity
AI 正在改变安全漏洞被发现和利用的速度,而最明确的应对方式,是让安全团队将高能力模型用于自身的防御工作。
当我们公开发布 Claude Security 测试版时,我们也同步公布了一批基于 Claude Opus 进行构建的技术与服务合作伙伴,因为对于不同团队而言,最快的采用路径各不相同:有些团队可能直接使用 Claude,有些通过他们已有的平台来使用,还有些则通过熟悉其环境的服务合作伙伴来使用。
其中多项方案现已上线,初步结果展示了前沿模型防御在实际应用中的样貌。
初步成果
合作伙伴报告称,由 Opus 驱动的防御能力在内部和客户环境中均取得了显著提升:
- 每周对超过 15 万个生产资产进行持续渗透测试,每周发现数千个已验证的高危和严重级别发现项,且零误报(Wiz,在客户生产环境中)。
- 相当于一整年的渗透测试工作量在三周内完成(Palo Alto Networks,内部测试)。
- 安全测试覆盖率从约 10% 提升至超过 80%,覆盖 1600 个应用和超过 50 万个 API,扫描周期从 3-5 天缩短至不到一小时(Accenture,在其自身基础设施上)。
相关工作分为三个领域:大规模进攻性测试、缩小发现与修复漏洞之间的差距,以及将受管控的 AI 部署到生产环境中。
生产规模下的持续进攻性测试
进攻性测试意味着像攻击者那样攻击你自己的系统,从而让你率先发现可利用的攻击路径。
Wiz Red Agent 是一款由 AI 驱动的攻击工具,它利用 Opus 像人类渗透测试人员一样,在生产级 Web 应用和 API 中进行推理。它能分析应用逻辑、串联攻击步骤,并实时适应服务器响应,从而发现传统扫描器遗漏的逻辑驱动型漏洞。该工具每周持续扫描超过 15 万个生产资产,能够发现数千个高危和严重级别的安全问题,每个发现都通过 Wiz 安全图谱验证了可利用性并提供了业务背景。Wiz 公司 AI 与威胁研究副总裁 Alon Schindel 表示:“安全团队不再受限于数据不足,而是受限于采取行动的能力。通过将前沿模型嵌入 Wiz 智能体,我们正在帮助组织以 AI 的速度进行防御。”
Unit 42 前沿 AI 防御是 Palo Alto Networks 提供的专家主导服务,它利用 Opus 发现隐藏漏洞,绘制这些漏洞如何串联成关键攻击路径,并制定针对 AI 驱动攻击的加固路线图。该服务将暴露分析与机器级防御的基准蓝图以及实际转型工作相结合。Palo Alto Networks Unit 42 高级副总裁 Sam Rubin 表示:“随着攻击者利用前沿模型来自动化网络攻击,防御方必须更快地行动。”
CrowdStrike 的前沿 AI 就绪与韧性服务将同类能力引入到一个受超过 60% 的《财富》500 强企业信赖的平台中,它将 Opus 与 CrowdStrike 的 AI 红队服务及专有智能体框架相结合,持续搜寻客户应用中的潜在零日漏洞,验证发现结果,并在新代码进入生产环境之前加速修复。
“像 Anthropic 的 Claude Opus 这样的前沿模型,正在赋予防御方一年前还不存在的能力优势,将漏洞管理全面向左移。”——CrowdStrike 全球咨询服务副总裁 Mark Manglicmot
缩小发现与修复之间的差距
发现漏洞与修复漏洞之间的差距,正是大部分漏洞暴露风险所在,因为分类、优先级排序、补丁测试以及跨团队交接都需要时间。
埃森哲的 Cyber.AI 是一个智能体平台,它将资产、身份、威胁和管控措施连接成一个统一的操作模型,Opus 在此模型上进行推理,将检测、优先级排序和修复作为持续循环来运行。埃森哲首先在内部进行了大规模验证:将其安全测试覆盖率从大约 10% 提升至超过 80%,覆盖了 1,600 个应用程序和超过 50 万个 API,并在其自身的全球 IT 基础设施中将扫描周转时间从 3-5 天缩短至不到一小时——这些成果正是 Cyber.AI 现在为客户提供的服务的基础。
“企业领导者正在应对历史上发展最快、最复杂的网络威胁格局。我们正在与 Anthropic 合作,提供客户所需的工具,以保持领先地位。”——埃森哲网络安全全球负责人 Harpreet Sidhu
TrendAI™ Vision One 利用 Opus 辅助的漏洞研究,帮助遍布 185 个国家的企业通过虚拟补丁识别暴露面并降低风险。经过验证的发现结果也会流入 TrendAI 零日计划(Zero Day Initiative)进行协调披露,帮助在供应商发布补丁之前长达 96 天内保护易受攻击的系统。“随着人工智能加速漏洞发现,防御者面临的真正挑战变成了大规模修复,”TrendAI 首席平台与业务官 Rachel Jin 表示。“与 Anthropic 合作,我们正在帮助客户在攻击者利用漏洞之前,通过缓解措施和虚拟补丁来降低风险。”
德勤基于 Deloitte Ascend™ 构建的持续威胁暴露管理(CTEM)将发现、验证、优先级排序和修复作为一个工作流来运行,包括在不存在补丁时设计应对措施。Opus 的代码推理和自动化稳定性测试使团队有信心在数小时(而非数天或数周)内完成修复。“基于 Ascend 构建的 CTEM 旨在帮助减少漏洞修复中的决策延迟,”德勤合伙人兼美国网络业务负责人 Adnan Amjad 表示,“这个差距决定了攻击者和防御者谁能赢得时间窗口。”
让人工智能投入生产并得到治理
智能体式AI应用场景的新世界给许多团队带来了新的挑战。在没有清晰框架的情况下,为部署设置控制措施、审计证据和自主边界,往往会让AI在安全领域的应用陷入试点困境。
普华永道的Claude原生网络安全解决方案同时解决了首席信息安全官提出的两个问题:让AI安全地投入生产,以及实现网络安全职能本身的现代化。安全的AI采用方案将企业从沙盒环境到生产环境的周期从数月缩短至数周,并提供部署、治理和审计证据,帮助首席信息安全官和首席风险官满怀信心地将创新带给团队。规模化前沿防御方案则将Opus驱动的智能体推理能力集成到现有的漏洞管理、检测、安全工程和GRC工作流中,能够在既定的护栏和可审计性范围内实现自主执行。
“这是网络安全的一个决定性时刻,AI驱动的转型对于保持韧性和竞争力至关重要。”——摩根·亚当斯基,普华永道美国网络、数据与技术负责人
不断壮大的生态系统
波士顿咨询公司、印孚瑟斯和SentinelOne也正在基于Opus构建防御性网络安全产品,我们将在这些产品上线后分享更多细节。
上述所有产品都基于相同的底层Opus能力:对代码进行推理,理解哪些暴露点会转化为真实风险,以及维持长时间运行的智能体工作流。我们很高兴能与这些合作伙伴合作,通过最适合安全团队的接入点,将前沿防御带给更多安全团队。
了解更多关于Claude在安全领域的应用案例。
借助Claude改变您组织的运营方式。
Learn how companies like Wiz, Palo Alto Networks, and Accenture are using Claude Opus to find and fix vulnerabilities faster and deploy AI defense at scale.
- Category
- ProductClaude SecurityClaude Platform
- DateMay 21, 2026
- Reading time5min
- https://claude.com/blog/how-our-partners-are-putting-opus-to-work-for-cybersecurity
AI is changing how quickly security vulnerabilities are found and exploited, and the clearest response is for security teams to put highly capable models to work on their own defenses.
When we launched Claude Security in public beta, we also shared a set of technology and services partners building on Claude Opus, because the fastest path to adoption looks different for every team: some may use Claude directly, others through a platform they already run, others through a services partner who knows their environment.
Several of those offerings are now live, and the early results show what frontier-model defense looks like in practice.
Early results
Partners are reporting significant improvements in defense capabilities powered by Opus, both internally and in customer environments:
- Continuous pentesting across more than 150,000 production assets a week, surfacing thousands of validated high- and critical-severity findings weekly with zero false positives (Wiz, in customer production).
- The equivalent of a year's worth of penetration testing effort completed in under three weeks (Palo Alto Networks, internal testing).
- Security testing coverage taken from roughly 10% to over 80%, across 1,600 applications and 500,000+ APIs, with scan turnaround cut from 3–5 days to under an hour (Accenture, on its own infrastructure).
The work falls into three areas: testing offensively at scale, closing the gap between finding and fixing vulnerabilities, and deploying governed AI into production.
Continuous offensive testing at production scale
Offensive testing means attacking your own systems the way an adversary would, so you find the exploitable paths first.
Wiz Red Agent is an AI-powered attacker that uses Opus to reason like a human pentester across production web applications and APIs. It analyzes application logic, chains steps, and adapts to real-time server responses to surface the logic-driven flaws traditional scanners miss. Running continuously across more than 150,000 production assets a week, it's surfacing thousands of high- and critical-severity findings, each validated with proof of exploitability and business context from the Wiz Security Graph. "Security teams are no longer limited by a lack of data, but by the ability to act on it," said Alon Schindel, VP AI & Threat Research, Wiz. "By embedding frontier models into Wiz Agents, we're enabling organizations to defend at the speed of AI."
Unit 42 Frontier AI Defense is Palo Alto Networks' expert-led service that uses Opus to find hidden vulnerabilities, map how they chain into critical attack paths, and build a roadmap for hardening against AI-enabled attacks. The service pairs that exposure analysis with a benchmarked blueprint for machine-speed defense and hands-on transformation work. "As attackers weaponize frontier models to automate cyberattacks, the defense must move faster," said Sam Rubin, SVP of Unit 42, Palo Alto Networks.
CrowdStrike’s Frontier AI Readiness and Resilience Service brings the same class of capability to a platform trusted by more than 60% of the Fortune 500, pairing Opus with CrowdStrike's AI Red Team Services and proprietary agent frameworks to continuously hunt for latent zero-days in customer applications, validate findings, and accelerate remediation before new code reaches production.
"Frontier models like Anthropic's Claude Opus are giving defenders a capability advantage that didn't exist a year ago, pushing vulnerability management all the way to the left." - Mark Manglicmot, Global VP of Consulting Services, CrowdStrike
Closing the gap between finding and fixing
The gap between finding a vulnerability and fixing it is where much of vulnerability exposure lives, because triage, prioritization, patch testing, and cross-team handoffs all take time.
Accenture's Cyber.AI is an agentic platform that connects assets, identities, threats, and controls into a single operational model that Opus reasons across, running detection, prioritization, and remediation as a continuous loop. Accenture validated at scale internally first: taking security testing coverage from roughly 10% to over 80% across 1,600 applications and 500,000+ APIs, and cutting scan turnaround from 3–5 days to under an hour in their own global IT infrastructure – results that underpin what Cyber.AI now delivers to clients.
"Business leaders are navigating the fastest moving and most complex cyber threat landscape in history. We’re partnering with Anthropic to deliver the tools clients need to stay ahead." - Harpreet Sidhu, Global Lead, Accenture Cybersecurity
TrendAI™ Vision One uses Opus-assisted vulnerability research to help enterprises across 185 countries identify exposure and mitigate risk through virtual patching. Validated findings also flow into the TrendAI Zero Day Initiative for coordinated disclosure, helping protect at-risk systems up to 96 days before a vendor patch is available. “As AI accelerates vulnerability discovery, the real challenge for defenders becomes remediation at scale,” said Rachel Jin, Chief Platform and Business Officer, Head of TrendAI. “Together with Anthropic, we’re helping customers reduce risk through mitigation and virtual patching before attackers can exploit the gap.”
Deloitte's Continuous Threat Exposure Management (CTEM) built on Deloitte Ascend™ runs discovery, validation, prioritization, and remediation as one workflow, including countermeasure design when no patch exists. Opus's code reasoning and automated stability testing gives teams the confidence to remediate in hours rather than days or weeks. "CTEM built on Ascend exists to help reduce decision latency in vulnerability remediation," said Adnan Amjad, partner and US Cyber leader, Deloitte, "the gap helps determine whether attackers or defenders win the window."
Getting AI into production, governed
The new world of agentic AI use cases has presented a new challenge for many teams. Without clear frameworks, setting up the controls, audit evidence, and autonomy boundaries for deployment can often leave AI adoption for security in pilot purgatory.
PwC's Claude Native Cybersecurity offering addresses the two problems CISOs raise together: getting AI safely into production, and modernizing the cyber function itself. Secure AI Adoption moves enterprises from sandbox to production in weeks rather than quarters, with the deployment, governance, and audit evidence that helps the CISO and CRO bring innovation to their teams with confidence. Scaled Frontier Defense integrates Opus-powered agentic reasoning into existing vulnerability management, detection, security engineering, and GRC workflows, enabling autonomous execution within defined guardrails and auditability.
“This is a defining moment for cybersecurity, where AI-driven transformation becomes essential to staying resilient and competitive,” - Morgan Adamski, U.S. Cyber, Data & Tech Leader, PwC
The growing ecosystem
BCG, Infosys, and SentinelOne are also building defensive cyber offerings on Opus, and we'll share more on each as they become available.
Every offering above runs on the same underlying Opus capability: reasoning about code, understanding which exposures translate into real-word risk, and sustaining long agentic workflows. We're excited to be working with these partners to bring frontier defense to more security teams through the access points that fits them best.
Learn more about Claude for security use cases.