Anthropic Unveils Cyber Mission to Defend Critical Infrastructure and Scan Open-Source Software

Anthropic Unveils Cyber Mission to Defend Critical Infrastructure and Scan Open-Source Software

Anthropic has launched the Anthropic Cyber Mission, a long-term cybersecurity initiative focused initially on critical infrastructure and open-source software. The effort includes a new Critical Infrastructure Defense Program that brings Claude models, Anthropic engineers and threat research to infrastructure security providers, along with OSS Scanner, a free opt-in service that regularly checks open-source projects for vulnerabilities using the company’s strongest models.

Anthropic said the initiative is meant to help defenders respond to a widening gap between how quickly software flaws can be found and how slowly many of them are verified, prioritized and fixed. The company also pointed to the growing availability of highly capable AI models that can be used for offensive cyber activity.

The Critical Infrastructure Defense Program is starting with operational technology used in power grids, water systems and transportation networks, as well as government systems. Its 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

These organizations span consulting firms, cybersecurity vendors and industrial equipment makers that already work with critical infrastructure operators. Anthropic said several of them are using Claude to identify and repair vulnerabilities and to support customers doing the same.

The initial phase will focus on a smaller group of providers while Anthropic evaluates which approaches are practical and effective. Companies that build security products or services for critical infrastructure can register interest as the program expands.

Anthropic is targeting operational technology because these systems can be unusually difficult to secure. Industrial controllers and related software are often designed to remain in service for many years, and taking them offline for maintenance can carry significant operational risk. In some cases, known vulnerabilities can remain unresolved for long periods because patches cannot be applied safely while equipment is running.

Anthropic said AI cannot solve all of those problems, but it believes frontier models can help defenders find weaknesses and develop fixes before those vulnerabilities are exploited.

The new program extends work Anthropic began earlier with state, local, tribal and territorial governments. The company said it has since provided frontier Claude models and technical support to more than half of U.S. states and to several large public critical infrastructure operators, covering tasks such as code scanning, patching, incident response and red teaming.

The second part of the Cyber Mission is OSS Scanner, a free service for open-source maintainers that want automated vulnerability reports from Anthropic’s models. The scanner was developed in response to maintainers who asked to receive findings directly, including results that had not gone through human review.

Each report can include a proof of concept, an explanation of the vulnerability and a suggested patch when one is available. Anthropic said the reports are generated entirely by models and sent directly to participating maintainers without manual screening.

That approach is intended to speed up delivery, but it also means some reports may include mistakes, including incorrect severity assessments. Anthropic said it expects more than 90% of the scanner’s findings to be true positives.

In testing, Anthropic asked expert penetration testers to evaluate 97 critical and high-severity findings across 48 projects. The company said 85 of those met the standard for its coordinated disclosure process. Eleven others were valid issues that duplicated known vulnerabilities or other reports, while one was determined to be a false positive.

Over the previous six months, Anthropic said its models identified more than 29,000 candidate vulnerabilities. About 6,000 were manually reviewed and triaged, while nearly 5,000 unverified findings were sent directly to maintainers that had asked to receive all available results.

OSS Scanner is intended for projects with enough capacity to evaluate a high volume of findings. Anthropic said projects without that capacity will continue receiving human-verified reports through its existing coordinated vulnerability disclosure process.

The company is also planning to extend the open-source program beyond vulnerability discovery. Its stated next steps include automating more of the triage and patching process and researching new approaches to writing and hardening software.

The Cyber Mission builds on Project Glasswing, an earlier effort launched with companies including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, Nvidia and Palo Alto Networks. Anthropic previously committed up to $100 million in Claude usage credits and $4 million in direct donations through that initiative.

Project Glasswing has now been folded into Anthropic’s expanded Cyber Verification Program, with existing members moving into the program’s Specialized Access tier.

Anthropic said the Cyber Mission will continue expanding over the coming months, with more critical infrastructure partners and additional work around open-source software and supply-chain security. The company also said it plans to publish lessons from the program and collaborate with other AI developers, security companies and governments working on similar defensive efforts.

Anthropic’s broader forecast is that AI could increasingly favor defenders over the next two years by helping teams catch vulnerabilities earlier and build more secure software. The company cautioned, however, that the near-term environment may still favor attackers because exploiting flaws can happen faster than verifying and fixing them.

This analysis is based on reporting from Anthropic & unite.ai.

Image courtesy of Anthropic.

This article was generated with AI assistance and reviewed for accuracy and quality.

Updated Oct 8, 2026

About this article: This article was generated with AI assistance and reviewed by our editorial team to ensure it follows our editorial standards for accuracy and independence. We maintain strict fact-checking protocols and cite all sources.

Word count: 863Reading time: 0 minutes

📧 Stay Updated

Get the latest AI news delivered to your inbox every morning.

AI News Daily

Breaking Intelligence • Since 2023

Join hundreds of thousands of AI professionals who start their day with our curated newsletter. Get breaking news, expert analysis, and exclusive insights.

Stay Ahead of AI

Get the latest AI breakthroughs, tools, and insights delivered to your inbox every week.

✓ Free forever✓ Unsubscribe anytime✓ No spam guarantee

Go Premium

Unlock unlimited AI tools and an ad-free reading experience designed for AI professionals.

• Ad-free experience• Premium AI tools
Start Free Trial

14-day free trial • Cancel anytime
Plus $9/mo • Pro $90/yr (2 months free)

Follow Our Community

ChatAI

Breaking Intelligence

Your daily briefing on what matters in AI. Trusted by developers, researchers, executives, and AI enthusiasts worldwide.

© 2026 ChatAI. All rights reserved.