Anthropic Cyber Mission to Support Defenders with Tools, Research, and Resources
Anthropic launched a Cyber Mission pairing Claude, engineers, and partners to defend critical infrastructure and open-source projects.
Anthropic announced its Cyber Mission on October 8, 2026, combining Claude models, engineers, threat research, and funding to help defenders protect critical infrastructure and open-source software. The Critical Infrastructure Defense Program starts with 11 partners, including Accenture, CrowdStrike, Dragos, Palo Alto Networks, and Rockwell Automation, focused on operational technology that is difficult to patch safely. Free OSS Scanner gives opted-in maintainers model-generated reports with explanations, proof-of-concept details, and proposed patches without prior human review; Anthropic expects a true-positive rate above 90%. Six months of scanning produced more than 29,000 candidate vulnerabilities, of which about 6,000 were manually reviewed, and Project Glasswing has been folded into an expanded Cyber Verification Program.
- Anthropic launched Cyber Mission on October 8, 2026 for infrastructure and open source.
- Eleven partners include CrowdStrike, Dragos, Palo Alto Networks, Nozomi, and Rockwell Automation.
- OSS Scanner delivers unreviewed reports, proof-of-concept details, and proposed patches to opted-in maintainers.
- Six months of scanning yielded over 29,000 candidates; about 6,000 were manually triaged.
- Claude support has reached more than half of US states for public-sector security work.
Full article611 words · extracted from cybersecuritynews.com · click to collapse
Anthropic launched its Anthropic Cyber Mission on October 8, 2026, to help security teams protect critical infrastructure and open-source software. The effort combines advanced Claude models, engineers, threat research, and funding, with an emphasis on fixing weaknesses rather than simply producing more vulnerability reports.
The launch introduces the Critical Infrastructure Defense Program and OSS Scanner, a free service for participating open-source projects. Anthropic says the mission builds on Project Glasswing, where faster bug discovery exposed a difficult problem. Checking findings, setting priorities, and applying patches still require time and skilled people.
Protecting Critical Infrastructure
The Critical Infrastructure Defense Program brings Claude models, on-site engineers, and threat research to trusted providers serving power grids, water utilities, factories, transport networks, and government systems. Its 11 founding partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
These organizations support operational technology, or OT, which includes industrial controllers, control software, and networks that operate physical equipment. Many systems run for decades and cannot stop for routine updates. A poorly tested change could interrupt production or essential services, making patch deployment harder than in typical business networks.
Anthropic says several partners already use Claude to fix vulnerabilities and help customers address them. The initial group will test which approaches work safely in live environments. The company acknowledges that AI cannot solve every infrastructure security problem, especially when equipment, maintenance schedules, and operational safety limit available fixes.
The company says its government defense program has offered Claude models and technical support to more than half of US states since June, supporting code scanning, patching, incident response, and other public sector security work.
Free Open-Source Vulnerability Scanning
OSS Scanner offers regular security scans using Anthropic’s strongest models. Maintainers must opt in, and reports include an explanation, a proof of concept showing how a flaw can be exploited, and a proposed patch when available. Unlike Anthropic’s existing disclosure process, these reports arrive without human review.
That tradeoff speeds delivery but leaves maintainers responsible for checking accuracy and impact. Anthropic expects a true-positive rate above 90%, although severity ratings can be wrong. Projects without enough capacity to review raw findings will continue receiving human-verified reports through its coordinated vulnerability disclosure process.
The research behind OSS Scanner shows why this change matters. Anthropic reports more than 29,000 candidate vulnerabilities from six months of scanning, but only about 6,000 received manual review and triage. Those candidate findings should not be treated as confirmed flaws or completed fixes.
Earlier Cybersecuritynews coverage of Anthropic’s expanded Project Glasswing described efforts to move beyond detection into patching and other defensive tasks. The new mission extends that direction by pairing model access with engineering support and resources for maintainers.
Project Glasswing has also been merged into the expanded Cyber Verification Program. Cybersecuritynews previously covered its three access tiers, which separate defensive work, authorized penetration testing, and restricted testing of safety-critical systems. Applicants face verification requirements and security controls based on their work.
The Defender Advantage Fund supports pilot projects and keeps OSS Scanner free. Anthropic plans to expand infrastructure partnerships, improve automated triage and patching, and research safer software designs. Its stated goal is practical protection, measured by fewer exploitable weaknesses, reliable essential services, and faster recovery when attacks succeed.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.