rkj dev

Anthropic Unveils Critical Infrastructure Defense and Free OSS Scanner

The Anthropic Cyber Mission pairs frontier models and engineers with 11 industry partners while providing free vulnerability scans to open-source maintainers.

An industrial control room with engineers monitoring utility grids and control systems.
Illustration: Engineers monitoring utility operational technology and digital infrastructure networks.AI-generated illustration

Key takeaways

  • Anthropic launched the Cyber Mission, featuring the Critical Infrastructure Defense Program and a free automated OSS Scanner.
  • Eleven founding partners, including CrowdStrike, Palo Alto Networks, and Rockwell Automation, will work with on-site Anthropic engineers to protect operational technology.
  • OSS Scanner delivers automated, unverified vulnerability reports with proof-of-concept exploits and patches to eligible open-source maintainers.
  • Early evaluations across 48 open-source projects yielded an 88% verification rate for critical and high-severity findings, with only one false positive.
  • Project Glasswing has been formally merged into Anthropic's expanded Cyber Verification Program.

Anthropic has introduced the Anthropic Cyber Mission, an initiative targeted at protecting public utilities, transportation networks, and open-source software repositories from automated software exploits. Announced on October 8, 2026, the program is designed to deliver frontier artificial intelligence models, dedicated engineering personnel, and free security scanning tools directly to defenders of essential digital infrastructure.

According to Anthropic's official announcement, the initiative focuses on two distinct areas: hardening operational technology (OT) through the new Critical Infrastructure Defense Program (CIDP), and scanning widely used repositories through OSS Scanner, an opt-in vulnerability auditing service provided at no cost to open-source maintainers.

Industrial power substation and water pumps showing physical operational technology systems.
Illustration: Operational technology networks powering essential utilities and municipal services.AI-generated illustration

Protecting Operational Technology Across Critical Infrastructure

The Critical Infrastructure Defense Program focuses on defending the proprietary software and industrial controllers that operate power grids, municipal water facilities, manufacturing plants, and transit networks. These systems rely heavily on operational technology built to operate for decades without interruption. Operators rarely take these environments offline to patch software bugs, meaning known vulnerabilities often linger unresolved in active deployments.

To protect these systems, Anthropic has assembled an initial cohort of 11 founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Rather than offering basic API access, Anthropic is dispatching on-site engineers, threat research personnel, and frontier Claude models directly to these organizations, as reported by AI Weekly.

Industrial cybersecurity providers note that AI-enabled offensive tactics have made speed imperative. Palo Alto Networks stated that it is combining its Unit 42 threat intelligence with Anthropic models to defend operators, while CrowdStrike emphasized that industrial networks facing machine-speed attacks require defenses capable of matching that velocity. The program expands on Anthropic's previous public-sector work from June 2026, which provided defensive AI support to public infrastructure operators and more than half of all U.S. states, according to reporting from CyberScoop.

Software developer workspace displaying automated code audit findings and patch suggestions.
Illustration: Automated vulnerability detection analyzing open-source software codebases.AI-generated illustration

Fast-Track Vulnerability Audits With OSS Scanner

The second major component of the Cyber Mission is OSS Scanner, a free scanning pipeline inspired by Google's OSS-Fuzz. While enterprise users access code auditing capabilities through the commercial Claude Security product, OSS Scanner is tailored specifically for the open-source software ecosystem.

As detailed in Anthropic's research announcement, the company spent the last six months testing frontier models across major repositories. The scans discovered over 29,000 candidate vulnerabilities, but human analysts could only manually verify and triage approximately 6,000 of them. Because the review process created an operational bottleneck, maintainers frequently asked Anthropic to deliver raw, unverified reports in bulk so they could evaluate the findings internally.

OSS Scanner addresses that request by offering a fast track that bypasses manual review. Eligible projects receive periodic, fully model-generated audits powered by Anthropic's strongest models, including Claude Mythos. Each delivered report contains a technical explanation of the issue, a bisection indicating when the defect entered the codebase, an actionable proof-of-concept reproducer, and a suggested patch when possible.

Anthropic projects an overall true-positive rate above 90% for the scanner. In a benchmark evaluation of 97 critical and high-severity findings across 48 projects, human penetration testers determined that 85 issues (88%) satisfied coordinated disclosure standards. Eleven of the remaining reports pointed to genuine defects that duplicated known flaws, and only one report was classified as a false positive.

Early adopters in the open-source community report notable gains in triage speed. Noah Misch of PostgreSQL confirmed that several findings included fixes suitable for production use, allowing maintainers to resolve flaws before releases. OpenSSL Corporation maintainer Anton Arapov noted that the model-generated reports rivaled findings submitted by human researchers, while Todd Ouska of wolfSSL stated that 72 of 74 reports received were valid, resulting in five CVE assignments.

Cybersecurity analysts collaborating on defensive patch verification and threat research.
Illustration: Security professionals coordinating defensive audits and patch verification.AI-generated illustration

Eligibility, Integration, and the Defensive Balance

Maintainers who wish to join the service must meet criteria modeled on OSS-Fuzz, focusing on software that has a critical influence on infrastructure and user security. According to the OSS Scanner technical documentation, core maintainers can register by opening a pull request on the project's public GitHub repository containing a project.yaml file, a build Dockerfile, and an optional threat model document outlining severity preferences and out-of-scope code.

To ensure maintainers are not burdened by disclosure timelines, Anthropic does not enforce a 90-day coordinated disclosure clock on automated, unverified reports. Scans execute inside hardened, offline sandboxes, and projects that lack the resources to handle bulk automated feeds will continue to receive human-reviewed reports through Anthropic's standard vulnerability disclosure process. Maintainers can also access free Claude Max 20x subscriptions under the Claude for Open Source initiative.

The Cyber Mission builds directly on Project Glasswing, an industry initiative introduced on April 7, 2026, alongside partners such as Amazon Web Services, Google, Apple, and Microsoft. As detailed by Unite.AI, Glasswing has now been folded into Anthropic's three-tier Cyber Verification Program, transitioning existing participants into its Specialized Access tier. Direct donations and pilot efforts continue through the Defender Advantage Fund, which was established in August 2026 to support entities like the Python Software Foundation, the Apache Software Foundation, Alpha-Omega, and OpenSSF.

Anthropic estimates that within two years, artificial intelligence will tilt the balance toward defense by making it easier to discover flaws prior to deployment and verify secure code at scale. However, the company warns that the near term remains volatile because defensive remediation and physical OT patching continue to move slower than automated exploitation tools.

Frequently asked questions

What is the Critical Infrastructure Defense Program?

It is an Anthropic initiative that pairs frontier Claude models, threat intelligence, and on-site Anthropic engineers with 11 founding security and industrial partners to protect operational technology running power grids, water networks, transit systems, and government facilities.

How does OSS Scanner differ from Claude Security?

Claude Security is a commercial enterprise scanning product, whereas OSS Scanner is a free, opt-in service for critical open-source software projects that delivers automated vulnerability reports, reproducers, and patches directly from Anthropic's strongest models.

How can open-source maintainers apply for OSS Scanner?

Core maintainers of eligible projects can enroll by submitting a pull request to Anthropic's open-source GitHub repository with a configuration file, Dockerfile, and optional threat model description.

Are reports from OSS Scanner subject to a 90-day disclosure deadline?

No. Anthropic does not impose a 90-day public disclosure deadline on unverified, automated reports from OSS Scanner, allowing maintainers to review findings without forced deadlines.

Sources

  1. Introducing the Anthropic Cyber MissionAnthropic · Oct 8, 2026 · Official
  2. Launching an opt-in vulnerability-finding service for open-source softwareAnthropic · Oct 8, 2026 · Official
  3. OSS Scannerred.anthropic.com · Official
  4. Anthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source softwareCyberScoop · Oct 8, 2026
  5. Anthropic Launches Cyber Mission for Critical Infrastructure, Open SourceUnite.AI · Oct 8, 2026
  6. Anthropic Launches Cyber Mission With 11 Founding PartnersAI Weekly · Oct 8, 2026

How this story was made: the newsroom picked it up from Google News, latent.space and producthunt.com, gathered the full text of the sources above, and drafted it with AI assistance. Every factual claim was then checked against those sources before publishing (44 claims checked). Illustrations marked as AI-generated are not photographs. Spotted an error? Tell us.

#Anthropic #Cybersecurity #Critical Infrastructure #Open Source #Claude

Published October 9, 2026 at 01:07 UTC