Anthropic Launches Cyber Mission
- •Anthropic launches Cyber Mission to support defenders of critical infrastructure and open-source software
- •CIDP brings Claude models, on-site engineers, and threat research to 11 founding partners
- •Free OSS Scanner expects a true-positive rate above 90% and sends model-generated reports without human review
Anthropic launched its Cyber Mission on October 8, 2026, to help defenders secure critical infrastructure and open-source software with tools, research, engineering support, and funding. The effort begins with two programs: the Critical Infrastructure Defense Program (CIDP) and OSS Scanner. Anthropic says it plans to expand the work to additional areas.
CIDP brings frontier Claude models, on-site engineers, and threat research to providers protecting operational technology (OT), the controllers, software, and industrial networks used by power grids, water systems, factories, and transportation networks. Many OT systems cannot be taken offline for patches, so known vulnerabilities may remain unresolved for years. Founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Several partners are already working with Claude to fix vulnerabilities and help customers do the same. Anthropic says the first cohort will test which approaches are effective and practical.
OSS Scanner is a free, opt-in service that periodically scans enrolled open-source projects with Anthropic’s most capable models. Each report includes a proof of concept showing how a bug could be exploited, an explanation, and a suggested fix when available. Reports are generated by models and sent without human review, so they may include errors such as an incorrect severity rating. Anthropic expects a true-positive rate above 90% and says it will work to improve accuracy and fix quality. Projects without capacity to handle the findings will continue to receive human-verified disclosures under Anthropic’s coordinated vulnerability disclosure policy.
Anthropic says Project Glasswing scanned hundreds of widely used open-source projects, with people reviewing many potential vulnerabilities before private reports went to maintainers. Earlier this week, the company merged Glasswing into its expanded Cyber Verification Program, which gives more defenders access to its most capable models. Anthropic has also funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, the Apache Software Foundation, Akrites, and Gold Eagle. The Defender Advantage Fund, launched in August, supports pilot programs and helps keep OSS Scanner free. Eligible maintainers can also apply for free Claude Max subscriptions through Claude for Open Source.
Anthropic says highly cyber-capable AI models are now widely available to attackers, while defensive tools have not reached enough defenders. It forecasts that in two years AI will favor defense, making it easier to catch bugs before release, write secure software, and defend systems with models. In the near term, however, vulnerability exploitation costs have fallen while verification, disclosure, and fixes remain slow. Anthropic says Project Glasswing sometimes saw months between discovery and repair; OT repairs can take decades in rare cases when machinery cannot be safely stopped. Over the coming months, the company plans to bring CIDP to more partners and sectors and expand work on open-source software and the broader supply chain.