Menu
AI & EMERGING TECH

Anthropic Cyber Mission Targets Critical Infrastructure and Open-Source Security

Uday Patil Oct 8, 2026 10 min read 7 views
Anthropic Cyber Mission Targets Critical Infrastructure and Open-Source Security

Anthropic Cyber Mission is a new long-term cybersecurity initiative designed to strengthen critical infrastructure and open-source software using frontier Claude models, engineering support, threat research and funding.

Anthropic launched the program on October 8, 2026, with two initial priorities: protecting operational technology used in power, water, transportation and government systems, and helping open-source maintainers find and fix software vulnerabilities faster.

The initiative introduces a new Critical Infrastructure Defense Program and a free Anthropic OSS Scanner for qualifying open-source projects.

Anthropic says the effort reflects lessons from Project Glasswing, where AI models became increasingly capable of finding vulnerabilities but human teams remained a major bottleneck for verification, prioritization and remediation.

For broader coverage of AI-powered defensive security and emerging agentic threats, see our AI-Era Threats and Agentic Security Guide.

Key takeaway: Anthropic is moving beyond simply finding vulnerabilities. Its new Cyber Mission aims to help defenders verify findings, prioritize risk and actually fix weaknesses in critical infrastructure and open-source software.

What Is the Anthropic Cyber Mission?

The Anthropic Cyber Mission is a long-term cybersecurity program aimed at helping defenders protect systems that society depends on.

Anthropic is initially focusing on two areas:

  • Critical infrastructure and operational technology
  • Open-source software security

The company says increasingly capable AI models can help defenders find weaknesses faster, but vulnerability discovery alone does not automatically reduce cyber risk.

Security teams still need to confirm whether a finding is valid, assess how dangerous it is and safely deploy a fix.

Critical Infrastructure Defense Program Launches

The first major part of the initiative is Anthropic’s Critical Infrastructure Defense Program.

The program combines frontier Claude models, on-site Anthropic engineers and threat research with organizations that already protect operational technology and industrial environments.

The focus includes systems supporting:

  • Power grids
  • Water utilities
  • Transportation networks
  • Factories
  • Government systems
  • Industrial control environments

These systems are especially difficult to secure because they often use equipment designed to operate for decades.

Unlike conventional IT systems, many industrial systems cannot simply be restarted or taken offline whenever a security patch becomes available.

Why Operational Technology Is Hard to Patch

Operational technology, commonly known as OT, controls physical processes such as electricity generation, manufacturing equipment, pumps and transportation infrastructure.

Updating these systems can carry significant operational risk.

An incorrectly tested change can interrupt production, shut down essential equipment or create safety problems.

As a result, known vulnerabilities can sometimes remain unresolved far longer than they would in ordinary enterprise IT environments.

Anthropic believes AI can help defenders identify practical remediation strategies faster while still leaving final decisions to experienced operators and engineers.

11 Founding Partners Join the Program

Anthropic announced eleven founding partners for the Critical Infrastructure Defense Program:

  • Accenture
  • Booz Allen
  • CrowdStrike
  • Deloitte
  • Dragos
  • Hitachi
  • Insane Cyber
  • Nozomi Networks
  • Palo Alto Networks
  • PwC
  • Rockwell Automation

These organizations represent security vendors, consulting firms, industrial cybersecurity specialists, system integrators and equipment manufacturers.

Anthropic says several partners are already using Claude to identify and remediate vulnerabilities and to help their own customers address security weaknesses.

Claude Is Already Supporting US Government Cyber Defense

Anthropic says its earlier government cyber defense program has provided frontier Claude models and technical support to more than half of US states since June 2026.

The models have been used in workflows including:

  • Code scanning
  • Patch development
  • Incident response
  • Red teaming
  • Other defensive security tasks

The new Cyber Mission expands that model by working more closely with organizations that already support critical infrastructure operators.

Anthropic Launches Free OSS Scanner

The second major part of the initiative is OSS Scanner, a free opt-in security scanning service for eligible open-source projects.

Anthropic says participating projects will receive regular scans using its strongest models.

Each report may include:

  • A description of the vulnerability
  • A proof of concept
  • An explanation of how the issue can be exploited
  • A proposed fix when available

The service is designed for core maintainers capable of reviewing a high volume of security findings.

OSS Scanner Reports Are Not Human-Reviewed

One important limitation is that OSS Scanner findings are generated by Anthropic models and delivered without mandatory human review.

This allows maintainers to receive reports faster, but it also means some findings may contain errors.

Anthropic says incorrect severity ratings or misunderstandings of a project’s threat model are possible.

The company currently expects the scanner’s true-positive rate to exceed 90% and says it will continue improving accuracy and patch quality over time.

29,000 Candidate Vulnerabilities Found in Six Months

Anthropic says its models discovered more than 29,000 candidate vulnerabilities during approximately six months of open-source scanning.

However, the company was only able to manually review and triage around 6,000 of those findings.

This gap illustrates the central problem Anthropic is trying to address.

AI systems can generate vulnerability findings much faster than human security researchers can manually validate them.

The 29,000 figure should therefore not be interpreted as 29,000 confirmed security vulnerabilities.

Nearly 5,000 Raw Reports Were Sent to Maintainers

Anthropic says some maintainers asked to receive all model-generated reports for their projects without waiting for manual review.

Nearly 5,000 reports have already been provided this way.

This approach is intended for projects with enough engineering and security capacity to validate findings themselves.

Projects without sufficient resources can still receive human-reviewed findings through Anthropic’s coordinated vulnerability disclosure process.

Early Testing Shows High Signal in Critical Findings

Anthropic also tested an early version of OSS Scanner using expert penetration testers.

Researchers reviewed 97 high- and critical-severity findings across 48 projects.

According to Anthropic, 85 findings met the company’s coordinated vulnerability disclosure standards.

Of the remaining 12 findings, most were valid issues that duplicated known problems or other findings, while one was considered invalid.

These early results are encouraging, but they do not guarantee the scanner will always produce accurate results across every project.

Some OSS Scanner Findings Already Became CVEs

Anthropic says several open-source maintainers have already validated findings generated by its models.

In one example shared by the company, wolfSSL reported receiving 74 findings, with only two rejected and five ultimately becoming CVEs.

Other projects including PostgreSQL, OpenSSL and HotCRP also provided feedback indicating that many reports were detailed enough to support verification and remediation.

Why Anthropic Is Focusing on Open Source

Open-source software is embedded throughout modern technology infrastructure.

Many widely used projects are maintained by small teams or individual volunteers despite supporting large numbers of commercial products and services.

This can create a resource imbalance where maintainers receive more security reports than they can realistically review.

Anthropic says the Cyber Mission is intended to give those maintainers more defensive capability while also improving automated triage and patch generation.

Project Glasswing Is Being Folded Into a Larger Program

The Cyber Mission builds on Anthropic’s earlier Project Glasswing work.

Project Glasswing brought together major technology and security organizations to identify vulnerabilities in important software.

Anthropic says the initiative showed that vulnerability discovery alone does not necessarily lead to faster fixes.

Earlier this week, Project Glasswing was merged into the company’s expanded Cyber Verification Program.

The verification program gives qualified cybersecurity professionals access to advanced Claude cyber capabilities with reduced blocking based on approved defensive activities.

Cyber Verification Program Expands Claude Access

The expanded Cyber Verification Program includes three access tiers for different types of security work.

Qualifying teams can receive access to Anthropic’s most capable models, including:

  • Claude Opus 5.5
  • Claude Sonnet 5.5
  • Claude Mythos 5.1
  • Future supported models

Anthropic maintains stricter safeguards on generally available models because cybersecurity capabilities can be used for both defense and offensive activity.

The Defender Advantage Fund Supports the Mission

Anthropic is also using its Defender Advantage Fund to support defensive cybersecurity projects.

The fund helps finance pilot programs and allows OSS Scanner to remain free for participating open-source maintainers.

Anthropic has also funded organizations supporting widely used open-source projects and vulnerability coordination efforts.

Anthropic Says AI Currently Benefits Attackers Too

The company acknowledges that frontier AI models can also be used to exploit vulnerabilities and conduct cyber operations.

Anthropic argues that the short-term security environment remains challenging because AI has reduced the cost of discovering and exploiting vulnerabilities while verification and patching remain comparatively slow.

This creates a temporary imbalance where attackers may be able to move faster than many defenders.

Anthropic Predicts AI Could Eventually Favor Defenders

Anthropic says it expects that within roughly two years, AI may increasingly shift the advantage toward defenders.

The company believes models could make it easier to:

  • Find vulnerabilities before software ships
  • Generate safer software
  • Automate remediation
  • Support continuous defense
  • Reduce exploitable attack paths

However, Anthropic also acknowledges that reaching that point will require better workflows for validation, prioritization and deployment rather than simply producing more vulnerability reports.

Why Human Verification Still Matters

AI-generated cybersecurity findings can be valuable, but they still require contextual understanding.

A model may correctly identify a coding weakness while misunderstanding whether an attacker can realistically reach the vulnerable component.

It may also assign an incorrect severity rating or propose a fix that creates operational problems.

This is especially important in critical infrastructure, where a technically correct patch could still be unsafe to deploy during live operations.

What This Means for Security Teams

The Anthropic Cyber Mission reflects a broader shift toward using frontier AI models as active defensive tools rather than general-purpose assistants.

Security teams may increasingly use AI for:

  • Vulnerability discovery
  • Exploit reproduction
  • Patch generation
  • Code review
  • Threat analysis
  • Incident response
  • Security testing

Organizations adopting these tools should still maintain human review, approval controls and strong operational safeguards.

Frequently Asked Questions

What is the Anthropic Cyber Mission?

It is Anthropic’s long-term cybersecurity initiative focused initially on defending critical infrastructure and improving open-source software security.

What is the Critical Infrastructure Defense Program?

It is a program combining Claude models, Anthropic engineers and threat research with trusted organizations that secure operational technology and critical infrastructure.

What is Anthropic OSS Scanner?

OSS Scanner is a free opt-in service that periodically scans eligible open-source projects using Anthropic’s strongest AI models.

Are OSS Scanner findings confirmed vulnerabilities?

No. Reports are model-generated and may contain inaccuracies. Maintainers are responsible for validating findings before treating them as confirmed vulnerabilities.

How many vulnerabilities has Anthropic found?

Anthropic says its models produced more than 29,000 candidate vulnerability findings over roughly six months, but only around 6,000 received manual review and triage.

Does OSS Scanner provide patches?

Reports can include suggested fixes or candidate patches when the model is able to generate them.

Is the service free?

Yes. Anthropic says eligible open-source projects can receive OSS Scanner security scans at no cost.

Which organizations joined the critical infrastructure program?

The founding group includes Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

Final Takeaway

The Anthropic Cyber Mission represents a shift from using AI primarily to discover security weaknesses toward using it as part of a larger defensive workflow.

Anthropic is combining frontier Claude models with human expertise, engineering support, vulnerability verification and patching resources to protect both critical infrastructure and the open-source ecosystem.

The initiative also highlights an important reality: AI can find vulnerabilities faster than many organizations can currently verify and fix them.

The long-term success of AI-powered cybersecurity will therefore depend not only on how many vulnerabilities models can discover, but on how safely and quickly defenders can turn those findings into real risk reduction.

Stay Updated on AI Security

AI is rapidly changing both offensive and defensive cybersecurity operations.

Follow CyberUpdates365 for verified AI security news, vulnerability research, critical infrastructure developments and practical defensive guidance.

Official Sources

Anthropic Cyber Mission:
Introducing the Anthropic Cyber Mission

Anthropic OSS Scanner:
Launching an Opt-In Vulnerability-Finding Service for Open-Source Software

Anthropic Cyber Verification Program:
Expanded Cyber Verification Program

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.