Anthropic launches Cyber Mission with a Critical Infrastructure Defense Program and a free OSS Scanner
Synopsis
Anthropic announced the Anthropic Cyber Mission, a long-term cybersecurity commitment whose first two efforts are the Critical Infrastructure Defense Program (CIDP), which brings frontier Claude models, on-site engineers, and threat research to trusted providers defending operational technology such as power grids, water systems, and transportation networks alongside founding partners including Accenture, CrowdStrike, Palo Alto Networks, and Rockwell Automation, and OSS Scanner, a free opt-in service inspired by Google's OSS-Fuzz that gives open-source projects periodic scans from its strongest models with reports containing a proof of concept, an explanation, and a suggested fix, sent without human review and expected to exceed a 90% true-positive rate.
Interpretation
Introduces the Critical Infrastructure Defense Program (CIDP), which brings frontier Claude models, on-site engineers, and threat research to the trusted providers that protect operational technology, with founding partners Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Defensive tools had not yet reached enough of the defenders who need them; the program starts with a small cohort of providers to learn which strategies are most effective and practical, pairing model capability with existing operational-technology expertise. The text states the work is underway and that several partners are currently working with Claude to fix vulnerabilities and help customers do the same, while explicitly noting that critical infrastructure is hard to defend in many ways AI cannot fix, framing this as a first step.
Launches OSS Scanner, an opt-in service inspired by Google's OSS-Fuzz that gives enrolled open-source projects periodic scans from the strongest models free of charge, with each report including a proof of concept of how the bug could be exploited, an explanation, and a suggested fix where one is available. Under Project Glasswing the team scanned hundreds of widely used open-source projects, had humans triage and review many potential vulnerabilities, and privately reported findings through coordinated vulnerability disclosure; some maintainers with capacity to triage at scale asked for everything the models had found in their project, reviewed or not, and OSS Scanner responds to that request. Reports are model-generated and sent without human review, so maintainers receive them faster but some will contain inaccuracies such as a wrong severity rating; the text states an expectation of a true-positive rate above 90% and a commitment to improve the true-positive rate and fix quality over time.
Merges Project Glasswing into an expanded Cyber Verification Program that gives many more defenders access to the most capable models, and through the Cyber Mission deploys Anthropic engineering talent and provides tools and funding for those securing critical infrastructure and open-source software. The text notes that highly cyber-capable AI models are widely available to attackers now, but defensive tools, including Anthropic's own, have not yet reached enough of the defenders who need them; the merger widens access beyond a narrow set of defenders. The text reports that a June cyber defense program for state, local, tribal, and territorial governments has since offered frontier Claude models and technical support to more than half of all US states and some of the country's largest public critical infrastructure operators, speeding up code scanning and patching, incident response, red teaming, and other security workflows.
Funds and supports the open-source ecosystem by funding the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation, and by supporting Akrites and Gold Eagle, which collect and coordinate vulnerability reports from many sources to avoid overwhelming maintainers; the Defender Advantage Fund (0xDAF) supports pilot programs and keeps OSS Scanner free. Targets the bottleneck between finding and fixing vulnerabilities by aiming to automate triage and patching, which remain mostly manual, and to explore new secure architectures and coding practices, with a plan to share what works so other projects can replicate it. The text states this will be done based on guidance from open-source maintainers and foundations, and that maintainers can also apply to Claude for Open Source for free Claude Max subscriptions and to the Cyber Verification Program for expanded access to Claude's cyber capabilities for defensive work.
Perspective
The commitment is aimed at trusted providers that protect operational technology, open-source maintainers whose projects have the capacity to keep up with surfaced findings, and security teams of any size; the text states that CIDP's first step is to work with a small cohort of providers to learn which strategies are most effective and practical, with plans to bring it to more partners and more sectors over the coming months. OSS Scanner is meant for projects with the capacity to keep up with surfaced findings, while others continue to receive human-verified disclosures under the coordinated vulnerability disclosure policy. The text also says Anthropic will share what it learns, including what did not work, and expects other AI developers, security companies, and governments to run efforts of their own.
What the text offers is expectation rather than verified outcome: the above-90% true-positive rate for OSS Scanner is an expectation, reports sent without human review may contain inaccuracies such as a wrong severity rating, and fix quality is to be improved over time. CIDP is at the stage of learning with a small cohort of providers, so which strategies are most effective and practical remains to be summarized. The text also notes that in Project Glasswing months often passed between a vulnerability being found and being fixed, and that with operational technology a fix may have to wait until it can be applied safely to running machinery, in some rare cases possibly decades; whether AI favors defense in the near term is therefore uncertain, with the authors expecting the shift in about two years. The text does not give specific counts of projects scanned, vulnerabilities found, or fixes applied.
