Anthropic's 'Cyber Mission' Puts Claude and On-Site Engineers With 11 Infrastructure Security Firms, and Sends Open-Source Projects Unreviewed Model Scans
Anthropic launched the Anthropic Cyber Mission on Oct. 8 with two programs. The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers and threat research to 11 founding partners that secure operational technology, including Accenture, CrowdStrike, Dragos, Palo Alto Networks and Rockwell Automation. OSS Scanner gives enrolled open-source projects free periodic scans whose reports are model-generated and sent without human review; Anthropic says it expects a true-positive rate above 90%. All capability claims are Anthropic's own.

Anthropic is moving from giving defenders access to its models toward placing its own engineers with the companies that protect power grids and water systems, and toward sending open-source maintainers bug reports no human has checked. On October 8, Anthropic launched the Anthropic Cyber Mission, which it calls "a long-term commitment to securing the systems everyone depends on," starting with critical infrastructure and open-source software.
The Critical Infrastructure Defense Program
The program "brings frontier Claude models, on-site engineers, and our threat research" to the providers that operators rely on to secure operational technology: the controllers, control software and industrial networks behind grids, water utilities, factories and transport. Anthropic notes that such systems often cannot be taken offline to patch.
Its founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic says several partners are already working with Claude to fix vulnerabilities, and that its first step is "to work with a small cohort of providers to learn which strategies are most effective and practical." It also says it has offered frontier Claude models and technical support to more than half of all US states and some of the largest public critical-infrastructure operators since launching a program for state, local, tribal and territorial governments in June.
OSS Scanner: faster reports, no human review
Under Project Glasswing, Anthropic says, it scanned hundreds of widely used open-source projects, had humans triage many of the findings and reported them privately to maintainers. Some maintainers with capacity to triage at scale then asked for everything its models had found, reviewed or not; CyberScoop reports the same account.
The answer is OSS Scanner, an opt-in service "inspired by Google's OSS-Fuzz":
- Enrolled projects get periodic scans from Anthropic's most capable models, free of charge.
- Each report includes a proof of concept, an explanation, and a suggested fix where one is available.
- "The reports are model-generated and sent without human review." Anthropic says that means faster delivery but also that "some will contain inaccuracies, such as a wrong severity rating."
- Anthropic says: "We expect a true-positive rate above 90%." That is a forecast, not a measured result, and no independent test of it has been published.
- The service is meant for projects that can keep up with the findings; others will continue to get human-verified disclosures.
Anthropic says the Defender Advantage Fund it launched in August, which we covered at the time, keeps OSS Scanner free. Earlier this week it merged Project Glasswing into its expanded Cyber Verification Program.
Anthropic's own forecast
The launch post also puts a forecast on record: "in two years, AI will favor defense," but "in the near term, that may not be true." Anthropic says the cost of exploiting vulnerabilities has dropped while verifying, disclosing and fixing them "is slow and still depends on people," and that in Glasswing it often saw months pass between a vulnerability being found and fixed. For operational technology, it says, a fix may in rare cases wait decades.
That forecast frames the trade in OSS Scanner. Unreviewed reports move findings faster, which is the bottleneck Anthropic describes, but they also shift triage of any false positives onto maintainers. How that trade works out will show in maintainers' experience once projects enrol; neither Anthropic nor CyberScoop gives enrolment numbers yet.
Limits
- Every capability, partner role and the above-90% true-positive figure are Anthropic's statements; none has been independently verified. CyberScoop's report relays Anthropic's announcement and adds no independent testing.
- The OSS Scanner team's separate technical post was not read.
- The partner quotes on Anthropic's page are partners' own statements, published by Anthropic.
Sources
- Anthropic: Introducing the Anthropic Cyber Mission (October 8, 2026)
- CyberScoop: Anthropic rolls out program for 'long-term commitment' to secure critical infrastructure, open source software (October 8, 2026)
- Times of AI: Mythos 5 Goes Scan-and-Patch — Not a Chat Box — With $35M in Defender Credits
- Times of AI: Anthropic Opens Three Cyber Tiers — Red Team Hits Near-Unguarded Opus Rates