Anthropic on October 8, 2026, launched the Anthropic Cyber Mission, a long-term effort to equip defenders of critical infrastructure and open-source software with frontier models, on-site engineering support, and research. The company is starting with the Critical Infrastructure Defense Program for operational technology and the free, opt-in OSS Scanner for open-source projects.
What Happened
In a company blog post, Anthropic said the Cyber Mission supports defenders with tools, research, and resources. It begins with two tracks. The Critical Infrastructure Defense Program (CIDP) brings frontier Claude models, on-site engineers, and threat research to providers that secure power grids, water systems, transportation networks, and related operational technology. Founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
Separately, Anthropic launched OSS Scanner, an opt-in service that runs periodic vulnerability scans with its strongest models, including Claude Mythos, and delivers the findings free of charge. Reports include a proof of concept, explanation, and candidate patch when available. They are generated by the model and sent without human review.
Details
Anthropic said operational technology systems are often built to last decades and cannot easily be taken offline, so known vulnerabilities can persist for years. The CIDP focuses on the trusted providers that operators already rely on for advice about what is exposed and which fixes are safe. Several partners are already using Claude to fix vulnerabilities and help customers do the same, the company said. It has previously offered models and support to more than half of U.S. states and some large public critical infrastructure operators.
For open source, Anthropic drew on Project Glasswing experience. Over six months its models surfaced more than 29,000 candidate vulnerabilities; humans reviewed roughly 6,000. Some maintainers requested bulk unreviewed findings. OSS Scanner addresses that demand. Eligibility follows criteria similar to Google’s OSS-Fuzz: projects with critical impact on infrastructure and user security. Core maintainers enroll by submitting a pull request to Anthropic’s oss-scanner GitHub repository. Anthropic expects a true-positive rate above 90 percent and will refine the system based on feedback. In a validation of 97 critical and high-severity findings across 48 projects, 85 (88 percent) met the bar for its coordinated vulnerability disclosure process.
The company noted that in the near term attackers may retain an advantage because the cost of finding and exploiting vulnerabilities has fallen while verification and fixing remain human-dependent. It forecasts that within two years AI will favor defense.
Why It Matters
Frontier models are already available to attackers. Defensive access has lagged, particularly for operational technology environments that are hard to patch and for volunteer-maintained open-source projects that underpin most software. By routing models and engineers through established providers rather than directly to every operator, and by offering an opt-in fast path for maintainers who can triage volume, Anthropic is trying to close that gap without overwhelming smaller projects.
The unreviewed nature of OSS Scanner reports is a deliberate trade-off for speed. Anthropic has been transparent that some findings will be inaccurate or carry inflated severity ratings.
Context
The announcement builds on Project Glasswing and the expanded Cyber Verification Program. It also continues earlier work such as a cyber defense program for state, local, tribal, and territorial governments. Funding and free Claude Max access for open-source maintainers (Claude for Open Source) and the Defender Advantage Fund support related efforts.
Secondary reporting confirmed the 11 founding partners and the model-generated, unreviewed character of OSS Scanner reports. VentureBeat and SecurityWeek described prior Glasswing statistics: roughly 6,157 findings reported to maintainers and 516 patched in one accounting, with high true-positive rates on reviewed samples.
Impact
Operators of power, water, and transport infrastructure may see faster vulnerability discovery and remediation through their existing security and industrial partners. Open-source maintainers of eligible projects gain a free, recurring scan with reproducers and suggested patches, at the cost of needing to handle potential false positives. Projects without capacity will continue to receive human-verified disclosures under Anthropic’s coordinated process.
For the broader ecosystem, the move signals that frontier labs are moving from research demonstrations of vulnerability finding to production defensive tooling aimed at the sectors where patching is slowest.
What Next
Anthropic said it will expand the Cyber Mission to additional tools, research, and resources. It is soliciting interest from other companies that build security products or services for critical infrastructure. OSS Scanner enrollment is open via the public GitHub repository, with case-by-case eligibility decisions. The company plans to improve true-positive rates and automated triage and patching over time, guided by maintainer feedback.
TechPulse Takeaway
The October 8 launch is confirmed on Anthropic’s own site: a Critical Infrastructure Defense Program with 11 named founding partners focused on operational technology, and an opt-in OSS Scanner that delivers fully model-generated reports without human triage, inspired by OSS-Fuzz and informed by Glasswing. Claims about exact partner activities beyond “several are already working with Claude” and precise future true-positive rates remain company statements. The near-term attacker advantage and two-year defensive forecast are Anthropic’s assessment, not independent measurement.
Sources
- Anthropic, “Introducing the Anthropic Cyber Mission,” October 8, 2026: https://www.anthropic.com/news/anthropic-cyber-mission
- Anthropic, “Launching an opt-in vulnerability-finding service for open-source software,” October 8, 2026: https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source
- SecurityWeek, “Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security,” October 9, 2026: https://www.securityweek.com/anthropic-fast-tracks-ai-bug-reports-to-oss-maintainers-taps-11-firms-for-ot-security/
- VentureBeat coverage of Glasswing statistics, October 9, 2026
