Anthropic Cyber Mission Brings Claude Defense to Infrastructure and Open Source
Anthropic launches free AI security scans for open source code and an 11-partner program protecting power, water, transport and critical government systems.
Summary
Anthropic dated the Cyber Mission launch October 8, 2026, establishing a long-term defense effort for critical infrastructure, government systems and open-source software as frontier AI lowers attackers’ costs. Its Critical Infrastructure Defense Program supplies frontier Claude models, on-site engineers, funding and threat research to operational-technology providers Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Several partners already use Claude to repair vulnerabilities. The initial small cohort will test practical methods before expansion to more partners and sectors in coming months. A June program separately delivered Claude and technical support to more than half of US states and some of the largest public infrastructure operators for scanning, patching, incident response and red teaming.
OSS Scanner, a free opt-in service modeled on Google’s OSS-Fuzz, periodically scans projects with Anthropic’s strongest models and sends unreviewed, model-generated reports containing exploit proofs, explanations and suggested fixes. Anthropic expects over 90% true positives, warns that severity ratings and other details may be inaccurate, and limits the service to maintainers able to handle the volume. Projects needing support retain human-verified coordinated vulnerability disclosure. Project Glasswing scanned hundreds of widely used projects but exposed a bottleneck: findings are easier to generate than verify, prioritize and fix, with patches often taking months and rare operational-technology fixes decades. Glasswing was merged earlier that week into the expanded Cyber Verification Program. Anthropic plans automated triage and patching, secure-architecture research and wider supply-chain work, backed by August’s Defender Advantage Fund, or 0xDAF, and funding for the Python Software Foundation, Alpha-Omega, OpenSSF through the Linux Foundation, Apache Software Foundation, Akrites and Gold Eagle. Maintainers can seek free Claude Max subscriptions through Claude for Open Source or defensive access through the Cyber Verification Program. Anthropic forecasts AI may favor defense within two years, while acknowledging industrial systems cannot always be safely taken offline and AI cannot solve every risk.
Positives
- More than half of US states and several major public infrastructure operators have received frontier Claude models and technical support since June.
- Eleven founding partners will combine operational-technology expertise with Claude models, Anthropic engineers and threat research.
- OSS Scanner gives eligible open-source projects recurring security scans, exploit proofs and suggested fixes at no charge.
- Above 90% expected true positives could help capable maintainers identify consequential vulnerabilities faster.
- 0xDAF and funding for major open-source foundations support scanning, vulnerability coordination and future patch automation.
Risks & concerns
- OSS Scanner reports receive no human review, so severity ratings and other model-generated details may be inaccurate.
- Operational technology often cannot be taken offline, leaving known vulnerabilities unresolved for years and, rarely, decades.
- Project Glasswing found that verification, prioritization and repair remain slower than AI-powered vulnerability discovery.
- State-sponsored adversaries have established footholds across sectors, while AI further reduces the cost of finding and exploiting weaknesses.
- Small volunteer maintenance teams may lack the capacity to process the volume of vulnerabilities surfaced by automated scans.