Wain AI/Tech Blog

AI news and trends worldwide, updated nearly every day

Anthropic Launches the Cyber Mission: A Critical Infrastructure Defense Program and Free Vulnerability Scans for Open Source with OSS Scanner

Image: Anthropic official website

Anthropic Launches the Cyber Mission: A Critical Infrastructure Defense Program and Free Vulnerability Scans for Open Source with OSS Scanner

On October 8, 2026, Anthropic announced the Cyber Mission. It started the Critical Infrastructure Defense Program for companies that support infrastructure defense with 11 partners including Hitachi, and launched OSS Scanner, which delivers model-generated vulnerability reports to open-source projects for free without human review.

On October 8, 2026, Anthropic announced a long-term initiative it calls the “Anthropic Cyber Mission,” which supports the people who defend critical systems by supplying tools, research, and other resources1. It begins in two areas: the Critical Infrastructure Defense Program (CIDP), aimed at those who secure the operational technology (OT) that runs electricity grids, water utilities, and transport networks, and OSS Scanner, which gives open-source software (OSS) projects periodic vulnerability scans at no charge.

OSS Scanner reports go to maintainers as the model wrote them, with no human review or triage in between. Anthropic presents the service as an optional fast track that sits alongside its existing process, in which people verify findings before they are reported2.

CIDP supports the providers that infrastructure operators rely on

According to the announcement, OT consists of control hardware, the software that drives it, and plant networks, all designed to stay in service for decades, and because these systems often cannot be shut down for patching, known vulnerabilities can remain open for years1. Anthropic’s view is that operators, whatever their size, depend on a small number of trusted providers to tell them where they are exposed and which patches to apply to live systems.

CIDP delivers frontier Claude models, engineers who work on site, and Anthropic’s threat research to those providers. The eleven founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. They include consulting and advanced technology firms that operate security programs, security companies that guard corporate and plant networks, and manufacturers that build equipment and ship its patches. Several partners are already working with Claude on vulnerability fixes, and Anthropic plans to begin with a small cohort to learn which approaches work in practice.

Registration of interest is open to companies that sell security offerings to critical-infrastructure customers, such as security vendors, integrators, and equipment makers. The announcement does not describe a route for infrastructure operators to join directly, and it gives no pricing or duration. In a comment included with the announcement, Hitachi’s cybersecurity lead said that protecting the OT environments societies rely on is now among the most pressing priorities society faces.

Anthropic says it launched a cyber-defense initiative aimed at US state, local, tribal, and territorial governments in June 2026, and that it has since provided frontier models and technical help to over half of US states and to some of the biggest publicly run infrastructure operators in the country. Over the next few months it intends to bring CIDP to more partners and sectors and to share lessons, including approaches that failed.

OSS Scanner skips the human check

OSS Scanner grew out of a shortage of people to verify findings. According to a Frontier Red Team post, over the past six months Anthropic scanned a group of software projects it counts among the most important anywhere and turned up more than 29,000 candidate vulnerabilities, yet it could manually review and triage only about 6,000 of them2. Maintainers increasingly asked to receive everything, unverified reports included, along with proposed patches, and the company says it has sent close to 5,000 such reports directly.

OSS Scanner is the response: projects must opt in, and the design takes Google’s OSS-Fuzz as its model. Reports are produced by Anthropic’s strongest models, Claude Mythos among them, and are not reviewed by people. The company itself notes the trade-off: scans can run more quickly and more often, while some reports may be wrong. Each report comes with a self-contained reproducer, an explanation of the flaw (including, where possible, a bisection identifying when the bug first appeared), and a candidate patch when one is available.

Two different accuracy figures are given. In a check of an early build, the penetration testers who review Anthropic’s coordinated vulnerability disclosure (CVD) findings checked 97 critical- and high-severity reports from 48 projects: 85 (88%) met the CVD bar, 11 of the remaining 12 were genuine but repeated issues already known or found elsewhere in the scan, and just one turned out to be invalid2. Maintainers have also told Anthropic that severity ratings can come out too high or that the scanner misread a project’s threat model. The Cyber Mission announcement, for its part, says Anthropic expects more than 90% of findings to be true positives, and cautions that some reports may be inaccurate, for example by misjudging severity1.

The Frontier Red Team post also quotes projects that took part in testing. A wolfSSL representative said every one of the 74 reports it got held up except two, and that five were assigned CVEs, and curl’s Daniel Stenberg said the scanner found several issues, including one of the most serious curl flaws of the past few years2. Both statements are the projects’ own accounts.

Eligibility and how disclosure works

Eligibility follows criteria similar to OSS-Fuzz: projects whose weaknesses would seriously affect infrastructure and the security of users, decided case by case. The FAQ lists exposure to remote attacks, such as libraries that process untrusted input, and the number of users and dependent projects as considerations, and says Anthropic will verify by hand that each applicant is one of the project’s core maintainers before adding it3. It also states that the service targets projects that are already handling verified high- and critical-severity reports without falling behind.

To apply, a core maintainer opens a pull request against the anthropics/oss-scanner repository on GitHub that adds projects/<project>/project.yaml. The required fields are the repository URL, a primary contact email, and the path to a Dockerfile. That Dockerfile installs dependencies in advance and compiles the project; network access is available only while it builds, and the audit afterward runs offline. Optional additions include a threat model file describing what should be tested and what should be ignored, severity criteria, and preferred report formats; a GPG public key for encrypting report emails; and a disabled setting that pauses delivery.

Reports arrive by email as a bundle, and scanning continues periodically after the first pass, at a frequency that may depend on how many projects are enrolled, how widely a project is used, and other factors. Unverified findings carry no 90-day disclosure deadline of any kind. If a person later validates a report, Anthropic may disclose it under its CVD policy 90 days after notifying the project of that validation. The FAQ adds that Anthropic may one day apply a disclosure period to some high-severity reports, in which case it will give advance notice and let projects opt out. Projects that leave go back to receiving only standard CVD reports.

The path from Glasswing

The announcement follows, earlier the same week, the news that Anthropic had split the Cyber Verification Program (CVP) into three tiers and merged Project Glasswing into it. Where the CVP determines who can use the cyber capabilities of Anthropic’s top models, the Cyber Mission can be read as a framework in which Anthropic runs scans itself and contributes engineers, tools, and funding to support defenders.

Through Glasswing, Claude Mythos Preview was released in April 2026 on a limited basis to cyber defenders and critical infrastructure providers. In September, Claude Security, which scans codebases for vulnerabilities and drafts patches for human review, began running on Mythos 5.1. Anthropic describes Claude Security as an enterprise product, while OSS Scanner layers on token-intensive experimental methods and audits open-source projects free of charge3.

In the announcement, Anthropic concedes that although Glasswing surfaced many vulnerabilities, cyber risk has not yet fallen enough1. Finding vulnerabilities has become easier, but confirming, ranking, and repairing them is still hard, and months often passed between discovery and repair. The company forecasts that AI will favor defenders in two years, while acknowledging that this may not hold in the near term. On the OSS side, it has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation, and says the Defender Advantage Fund (0xDAF) it launched in August keeps OSS Scanner free.

Before a maintainer opts in

Whether to sign up for OSS Scanner likely depends on how a project is staffed. Because unverified reports can carry wrong severity ratings, the work of reproducing and judging each one moves to the maintainers. Anthropic’s own statement that OSS Scanner targets projects already handling verified reports without falling behind is a useful yardstick. Projects that enroll can use the threat model file to state up front what the scanner should ignore and how they grade severity, which leaves less to the scanner’s guesses.

Projects that do not enroll will still receive human-verified reports through CVD as before. Maintainers also have other options: Claude for Open Source, which offers free Claude Max, and applying to the CVP. For CIDP, the companies eligible to register interest are those that serve critical-infrastructure customers, and Hitachi, a Japanese company, is one of the founding partners. Pricing and how operators would receive the program have not been disclosed, so the details will have to wait for later announcements as it expands.

Sources

  1. Introducing the Anthropic Cyber Mission - Anthropic official announcement (October 8, 2026)
  2. Launching an opt-in vulnerability-finding service for open-source software - Anthropic Frontier Red Team (October 8, 2026)
  3. OSS Scanner - Anthropic Frontier Red Team (overview and FAQ)

We publish the latest AI news nearly every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →