Anthropic Launches Cyber Defense Effort With Free Scans and On-Site Engineers
The coordinated launch pairs support for critical-infrastructure security providers with an opt-in scanner whose findings reach maintainers without human review.
Loading page…
The coordinated launch pairs support for critical-infrastructure security providers with an opt-in scanner whose findings reach maintainers without human review.
Listen to this story
Anthropic’s October 8, 2026 Cyber Mission pairs direct support for critical-infrastructure operators with a faster, opt-in vulnerability scanner for open-source maintainers. Its Critical Infrastructure Defense Program will bring Claude models, on-site engineers and threat research to an initial small cohort serving sectors such as power, water and transportation, where decades-old operational technology can be difficult or unsafe to patch. OSS Scanner sends unreviewed reports, including proof-of-concept exploits and suggested fixes; Anthropic expects more than 90% true positives but warns of inaccuracies, leaving validation to participating maintainers.
Project Glasswing scanned hundreds of open-source projects, but months often passed between finding a vulnerability and fixing it.
OSS Scanner is intended for maintainers able to triage findings; Anthropic says it will continue human-verified disclosures for other projects.
The 11 founding partners include Accenture, Booz Allen, CrowdStrike, Dragos and Rockwell Automation.
Finding software flaws faster has not been enough to reduce cyber risk, Anthropic says. On October 8, 2026, it launched its Cyber Mission to help close that gap: engineers and Claude models for critical-infrastructure security providers, plus free scans for open-source projects. The scanner delivers findings faster by sending them without human review.
The effort builds on Project Glasswing, under which Anthropic scanned hundreds of widely used open-source projects and privately disclosed findings to maintainers after human review. The company says those discoveries have not yet produced a sufficient reduction in risk. In Glasswing, months often passed between finding a vulnerability and fixing it.
The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers and threat research to providers trusted by infrastructure operators. Its initial focus includes power grids, water systems and transportation networks, along with protecting government systems. Anthropic is starting with a small cohort to learn which approaches are practical and effective.
These environments run on operational technology: controllers, control software and industrial networks built to last decades. They often cannot be taken offline for patching. Equipment is proprietary, changes carry risks, and a mistake can shut down a plant. Anthropic acknowledges that many of these defense problems cannot be fixed by AI.
The 11 founding partners span consulting, security and equipment manufacturing. They include Accenture, Booz Allen, CrowdStrike, Dragos and Rockwell Automation. Anthropic says several partners are already using Claude to fix vulnerabilities and help their customers do the same.
It’s easier than ever to find vulnerabilities, but verifying, prioritizing, and fixing these findings remains challenging.
Anthropic, Cyber Mission announcement
OSS Scanner is a free, opt-in service that periodically checks enrolled open-source projects with Anthropic’s most capable models. It grew out of requests from maintainers who had enough capacity to assess findings themselves and wanted everything the models discovered, including results that had not been reviewed.
Anthropic expects a true-positive rate above 90%—meaning more than nine in ten flagged findings would be genuine vulnerabilities. But it warns that unreviewed reports can contain inaccuracies, including incorrect severity ratings. It says it will work to improve both the accuracy of findings and the quality of suggested fixes.
The service is intended for projects able to keep up with the findings. For others, Anthropic says it will continue sending human-verified disclosures. Its next goals include automating the still largely manual work of assessing and patching vulnerabilities, and researching ways to harden or rewrite code with projects that want to participate.
Loading discussion...
Join the conversation
Explain when faster delivery outweighs the burden of checking mistakes.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.