↓ Skip to main content
  1. Articles/

Anthropic Cyber Mission: A Free OSS Scanner and an 11-Partner Critical Infrastructure Program

·797 words·4 mins·
Florent Clairambault
Author
Florent Clairambault
CTO & software engineer — writing daily about spec-driven development and agentic coding

Anthropic Cyber Mission: A Free OSS Scanner and an 11-Partner Critical Infrastructure Program

Two days after expanding the Cyber Verification Program, Anthropic announced something broader on October 8, 2026: the Anthropic Cyber Mission, described as a long-term effort to help defenders secure software and systems. It starts with two areas, critical infrastructure and open-source software, and is planned to expand.

The framing is blunt. Anthropic writes that “highly cyber-capable AI models are widely available to attackers now,” and forecasts that “in two years, AI will favor defense”, while saying that may not hold in the near term. That is a more honest position than most vendor security pitches.

Critical Infrastructure Defense Program
#

The Critical Infrastructure Defense Program (CIDP) brings frontier Claude models, on-site engineers and threat research to trusted providers that protect operational technology: power grids, water systems, transportation networks and government systems.

The eleven founding partners:

  • Accenture
  • Booz Allen
  • CrowdStrike
  • Deloitte
  • Dragos
  • Hitachi
  • Insane Cyber
  • Nozomi Networks
  • Palo Alto Networks
  • PwC
  • Rockwell Automation

The first step is a small cohort, with expansion planned. Companies serving critical infrastructure can register interest through a form on claude.com. Note what is missing: no dollar figure for the Mission itself, and no list of operators. These are vendors and integrators, not utilities.

Anthropic is also candid about the hard part. In Project Glasswing, months often passed between discovering a vulnerability and fixing it. In OT, some fixes may need to wait for a safe window on running machinery, and in rare cases for decades. Finding bugs is the cheap half of the problem.

OSS Scanner
#

The part developers will care about most. OSS Scanner is an opt-in service, inspired by Google’s OSS-Fuzz, that gives open-source projects periodic free scans from Anthropic’s most capable models. Each report includes a proof of concept, an explanation and, where available, a suggested fix.

Two details deserve attention:

  1. No human review. Reports are model-generated and sent as-is, so some may contain errors such as wrong severity ratings. Anthropic expects a true-positive rate above 90% and aims to improve it.
  2. A fallback for overwhelmed maintainers. Projects without capacity to handle the volume still receive human-verified disclosures under Anthropic’s coordinated vulnerability disclosure policy.

A 90% true-positive rate sounds high, and it is still one false report in ten. For a volunteer maintainer, triage time is the scarce resource. Proof-of-concept exploits attached to each report help, because a failing PoC is a far better bug report than a paragraph of prose.

Funding the humans in the loop
#

AI-found vulnerabilities create a flood problem for maintainers, and Anthropic acknowledges it. It has funded the Python Software Foundation, Alpha-Omega and OpenSSF (through the Linux Foundation) and the Apache Software Foundation, and supported Akrites and Gold Eagle, which coordinate vulnerability reports so maintainers aren’t overwhelmed. The Defender Advantage Fund (0xDAF), launched in August, supports pilot programs and keeps OSS Scanner free. Maintainers can also apply to Claude for Open Source for free Claude Max subscriptions, and to the Cyber Verification Program for expanded defensive access.

Where this leaves Project Glasswing
#

Anthropic says Project Glasswing, in which partners scanned hundreds of widely used open-source projects and reported findings through coordinated disclosure, was merged into the expanded Cyber Verification Program earlier this week. The Cyber Mission reads as the next step: Glasswing was a managed pilot with selected partners, while OSS Scanner turns the same idea into an opt-in service any project can join. The state and local government program, launched in June, is part of the same family of efforts, and Anthropic says it has offered Claude models and technical support to more than half of US states.

What to do as a maintainer or a team
#

  • Maintainers: opt in if you can absorb reports, and write a SECURITY.md that says how you want them. Expect to verify the PoC before trusting severity.
  • Security teams: the Cyber Verification Program, covered in our earlier piece, is the route to fewer refusals on defensive work.
  • Spec authors: put security properties in the spec, not in a post-hoc scan. A scanner is a safety net for what the spec missed.

Our take
#

The strategic logic is clear: if frontier models make attackers faster, the same models have to be pointed at the code everyone depends on, and the maintainers need funding to cope. Releasing a scanner without funding triage would have been irresponsible; Anthropic did both.

The open questions are real. Unreviewed reports will test the 90% claim in public. The CIDP list is vendor-heavy. And “defense will win in two years” is a forecast, not a result. But shipping a free scan service for open source, with the failure mode stated up front, is the kind of concrete step that beats another policy white paper.

Sources
#

Related