rkj dev

Anthropic Launches Cyber Mission and Free Scanner for Open Source

The initiative pairs 11 industry partners to protect operational technology while offering automated security scans to open-source maintainers.

An illustration of industrial machinery and filtration pipes in a municipal water plant.
Illustration: Municipal water utilities and physical infrastructure systems targeted for cyber defense support.AI-generated illustration

Key takeaways

  • Anthropic launched the Cyber Mission on October 8, 2026, comprising the Critical Infrastructure Defense Program and the free OSS Scanner.
  • Eleven founding partners, including CrowdStrike, Palo Alto Networks, and Rockwell Automation, will deploy Claude models and engineering support to secure operational technology.
  • OSS Scanner sends fully automated vulnerability reports and candidate patches directly to maintainers, targeting a true-positive rate above 90%.
  • Data from Anthropic's disclosure dashboard shows models discovered 29,439 candidate vulnerabilities, but only 516 have been patched upstream so far.

Anthropic announced the Anthropic Cyber Mission on October 8, 2026, creating a dedicated initiative to defend essential services and shared code from machine-speed cyber threats. The effort focuses on two primary areas: protecting operational technology across public utilities through the Critical Infrastructure Defense Program, and providing continuous vulnerability auditing to developers through a free service named OSS Scanner.

The announcement comes as artificial intelligence tools increasingly alter defensive and offensive digital operations. Anthropic warned that highly cyber-capable models are already accessible to threat actors, while defensive teams face chronic staffing shortfalls. Although the company forecasts that AI capabilities will favor defenders within two years, it stated that the immediate dynamic remains asymmetric, with automated exploitation proving faster and cheaper than human remediation.

Protecting Operational Technology Across Critical Sectors

The first pillar of the initiative, the Critical Infrastructure Defense Program, targets operational technology running power grids, municipal water utilities, transportation networks, and factories. These environments rely heavily on controllers and industrial networks built to operate for decades without downtime. Because operators rarely have windows to take industrial equipment offline for updates, unpatched flaws often persist for years.

To address these constraints, Anthropic partnered with 11 founding organizations: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation, as reported by The Next Web. The program routes frontier Claude models, on-site Anthropic engineers, and threat intelligence to these service providers, who already advise plant operators and build industrial hardware.

An illustration of a technician inspecting legacy electronic controllers inside an electrical utility substation.
Illustration: Operational technology networks and legacy controllers that run public utilities.AI-generated illustration

Operational constraints in industrial systems present distinct hurdles that software models cannot resolve alone. In its announcement, Anthropic acknowledged that operational technology is difficult to defend in ways AI cannot fix. According to reporting from Axios, the company has not publicly clarified who covers computing expenses or whether founding partners receive subsidized model access. However, according to Anthropic, several partners are currently working with Claude to fix vulnerabilities.

The program expands on a previous public-sector rollout started in June 2026, which Anthropic stated offered Claude models and technical support to state, local, tribal, and territorial governments across more than half of all US states.

Free Automated Auditing for Open-Source Software

The second pillar, OSS Scanner, provides free, recurring vulnerability scans for open-source repositories that underpin modern digital infrastructure. The opt-in tool takes inspiration from Google's OSS-Fuzz initiative and uses Anthropic's most capable models, including Claude Mythos.

Unlike traditional coordinated disclosure channels that employ manual verification, OSS Scanner delivers fully model-generated reports directly to enrolled maintainers without human triage. Each notification includes a proof-of-concept reproducer, an explanation of the vulnerability, and a suggested patch when available. Anthropic acknowledged that removing manual reviews means reports could misjudge severity ratings or suggest flawed patches, but emphasized that automated delivery allows defenders to receive alerts far faster.

An illustration of a software developer reviewing code on computer screens.
Illustration: Open-source maintainers evaluating vulnerability findings and patches.AI-generated illustration

Penetration testers evaluating the scanner examined 97 critical- and high-severity findings across 48 projects, as covered by VentureBeat. Of those evaluations, 85 met disclosure thresholds, 11 were genuine vulnerabilities that duplicated existing issues, and only one was a false positive. Maintainers who tested earlier iterations reported notable successes: Todd Ouska of wolfSSL noted that out of 74 reports received, 72 were valid and five became Common Vulnerabilities and Exposures (CVE) designations. Daniel Stenberg reported that the scans surfaced multiple issues in curl, including one of the project's most severe flaws in recent years.

Maintainers register for OSS Scanner via GitHub pull requests. To manage legal risk, Anthropic's service terms require maintainers to verify reports independently and cap company liability at $1,000.

The Widening Gap Between Discovery and Remediation

While AI systems excel at scanning large codebases, fixing discovered flaws remains a manual bottleneck. According to VentureBeat, Anthropic's coordinated vulnerability disclosure dashboard recorded 29,439 potential findings between November 1, 2025, and October 2, 2026. Of those, 6,157 were formally reported across 591 open-source projects, yet only 516 had been patched upstream by early October.

This lag highlights a fundamental friction: automated models generate reports at scale, but volunteer maintainers and utility operators struggle to digest, verify, and implement solutions. Anthropic noted that even when upstream patches are published, downstream adoption across enterprise environments is not guaranteed. In operational technology, deploying patches to running hardware can sometimes take years or even decades.

Physical infrastructure remains under active threat. On July 30, 2026, the Federal Bureau of Investigation and the Environmental Protection Agency issued a joint advisory after cyberattacks targeted internet-exposed Rockwell Automation Allen-Bradley MicroLogix controllers across water utilities in at least seven states, causing flooding and loss of water pressure. Federal authorities recommended disconnecting programmable logic controllers from public internet exposure using gateways and firewalls.

Funding and Broader Defensive Initiatives

To sustain open-source scanning without imposing costs on volunteer developers, Anthropic is backing the initiative through its Defender Advantage Fund (0xDAF), launched in August 2026, as noted in the official announcement. The company also directed funding to key ecosystem stewards, including the Python Software Foundation, the Apache Software Foundation, and the OpenSSF and Alpha-Omega initiatives under the Linux Foundation. Organizations such as Akrites and Gold Eagle received support to help coordinate disclosures and prevent maintainer fatigue.

For defense teams seeking deeper model integration, Anthropic merged its earlier Project Glasswing research into an expanded Cyber Verification Program, offering vetted security professionals access to frontier model capabilities. Open-source developers can also apply to the Claude for Open Source program to obtain free Claude Max subscriptions.

Federal policymakers have begun proposing statutory backing for similar defenses. Representative Josh Gottheimer introduced the AI Cyber Defense Act, which would authorize $100 million for a Cybersecurity and Infrastructure Security Agency pilot between 2027 and 2031 to fund model access for critical operators. Over the coming months, Anthropic plans to invite additional operational partners to the program and research new ways of writing software and defending systems.

Frequently asked questions

What is the Anthropic Cyber Mission?

It is a security initiative launched by Anthropic on October 8, 2026, designed to protect critical infrastructure through partner collaborations and provide free, automated vulnerability scanning for open-source software repositories.

How does OSS Scanner differ from previous disclosure programs?

OSS Scanner sends model-generated vulnerability reports, explanations, and candidate patches directly to enrolled maintainers without human triage, trading manual review for delivery speed while targeting an accuracy rate above 90%.

Which companies joined the Critical Infrastructure Defense Program as founding partners?

The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.

What challenges remain in applying AI to critical infrastructure defense?

Operational technology runs on legacy controllers that cannot be taken offline easily, meaning verified fixes can take months or years to deploy safely to active machinery without interrupting power, water, or transport services.

Sources

  1. Introducing the Anthropic Cyber MissionAnthropic · Oct 8, 2026 · Official
  2. Anthropic signs CrowdStrike, Hitachi and 9 more to defend power and waterTNW | Anthropic · Oct 9, 2026
  3. Anthropic's Cyber Mission starts with 6,157 findings reported to maintainers and 516 patchedventurebeat.com · Oct 9, 2026

How this story was made: the newsroom picked it up from Google News, the-decoder.com and theverge.com, gathered the full text of the sources above, and drafted it with AI assistance. Every factual claim was then checked against those sources before publishing (25 claims checked). Illustrations marked as AI-generated are not photographs. Spotted an error? Tell us.

#Anthropic #Cybersecurity #Critical Infrastructure #Open Source #Claude #Vulnerability Management

Published October 10, 2026 at 01:55 UTC