Anthropic Launches Cyber Mission to Protect Critical Infrastructure and Open-Source Software With Claude AI
Anthropic launched Cyber Mission: Claude-powered critical infrastructure defense with 12 security partners plus a free OSS Scanner for automated vulnerability reports.
Anthropic's Cyber Mission comprises the Critical Infrastructure Defense Program (CIDP), which brings frontier Claude models, on-site engineers, and threat research to OT environments through partners including CrowdStrike, Dragos, Palo Alto Networks, and Rockwell Automation, and a free opt-in OSS Scanner that delivers unreviewed vulnerability reports with exploit reproducers, explanations, and proposed patches. Anthropic says its models identified over 29,000 candidate vulnerabilities in six months with only about 6,000 manually triaged; of 97 critical/high findings reviewed by pen testers, 85 met coordinated-disclosure criteria. The initiative builds on Project Glasswing and the expanded Cyber Verification Program, and follows a government program supporting cyber defense in more than half of U.S. states.
- CIDP pairs Claude models and engineers with OT partners like Dragos, Nozomi, Rockwell
- OSS Scanner sends findings without human review; maintainers must validate and prioritize
- 29,000+ candidate vulnerabilities found in six months; only ~6,000 manually triaged
- Of 97 pen-tested critical/high findings, 85 qualified for coordinated disclosure
- Government cyber defense program already active in over half of U.S. states
Full article533 words · extracted from gbhackers.com · click to collapse
Anthropic launched its Cyber Mission, a long-term initiative aimed at helping defenders secure critical infrastructure and open-source software. This initiative utilizes frontier Claude models, offers engineering support, conducts threat research, and provides funding.
The Cyber Mission introduces two key components: the Critical Infrastructure Defense Program (CIDP) and the OSS Scanner, a free, opt-in service for discovering vulnerabilities.
These initiatives address a growing concern: while AI makes it easier to identify vulnerabilities, the processes of validating findings, coordinating disclosures, and deploying fixes remain resource-intensive.
Cyber Mission
The CIDP specifically targets operational technology that supports power grids, water utilities, factories, and transportation networks. These environments rely on industrial controllers, proprietary software, and equipment designed to function for decades.
Unlike conventional enterprise systems, industrial assets often cannot be taken offline for patching. Even small changes require careful validation, as an improper update can disrupt production or compromise essential services.
Anthropic plans to provide frontier Claude models, on-site engineers, and threat research through established infrastructure security providers and equipment manufacturers.
Founding partners for this initiative include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
Several of these partners are already using Claude to identify and repair vulnerabilities and assist clients with remediation. Anthropic will initially work with a selected group of partners to determine which approaches are suitable for live industrial environments.
The company also reported that its government cyber defense program has supplied models and technical support to more than half of U.S. states, aiding in code scanning, patching, incident response, and red teaming.
The OSS Scanner delivers periodic assessments using Anthropic’s most advanced models. Reports include an exploit reproducer, an explanation of the vulnerability, and a proposed patch when applicable. Findings are provided without human review, allowing for faster delivery but placing the onus for verification and prioritization on the maintainers.
Anthropic’s research highlights a validation bottleneck: its models identified over 29,000 candidate vulnerabilities in a six-month period, but only around 6,000 underwent manual review and triage. It is important to note that these figures represent candidate findings rather than confirmed vulnerabilities.
In an initial evaluation, penetration testers reviewed 97 critical and high-severity findings across 48 projects. Of these, eighty-five met Anthropic’s criteria for coordinated disclosure, eleven identified real but duplicate issues, and one was deemed invalid.
The company cautioned that severity ratings may be inflated or that threat models may be misunderstood.
For projects that lack the capacity to process automated reports, human-verified disclosures will continue to be provided through Anthropic’s existing coordinated vulnerability disclosure process.
The Cyber Mission builds upon Project Glasswing and the expanded Cyber Verification Program, shifting focus toward resolving findings rather than merely generating them.
Future work will involve automated triage, patching, secure architecture research, and software supply-chain protection. Anthropic recognizes that while AI can assist, it cannot eliminate operational constraints; the success of defensive measures ultimately depends on verified fixes, safe deployment, and collaboration with maintainers and infrastructure operators.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.