
Anthropic Launches Cyber Mission to Defend Critical Infrastructure and Open Source
Anthropic has launched the Anthropic Cyber Mission, a long-term effort to support defenders with frontier models, engineering talent, and funding. Initial programs target operational technology and open-source software security.
Anthropic announced the Anthropic Cyber Mission on October 8, 2026, a long-term commitment to securing the systems everyone depends on. The effort will support defenders with tools, research, and resources, starting with two areas: critical infrastructure and open-source software.
Defending Critical Infrastructure
The company introduced the Critical Infrastructure Defense Program (CIDP), which brings frontier Claude models, on-site engineers, and threat research to the providers that protect the operational technology behind power grids, water systems, and transportation networks. Founding partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
Operational technology often cannot be taken offline to patch, so known vulnerabilities can stay unresolved for years. Anthropic said several partners are already working with Claude to fix vulnerabilities and help customers do the same. The first step is to work with a small cohort of providers to learn which strategies are most effective and practical.
Earlier this week, Anthropic merged Project Glasswing into its expanded Cyber Verification Program, giving more defenders access to its most capable models. In June, the company launched a cyber defense program for state, local, tribal, and territorial governments, and has since offered frontier Claude models and technical support to more than half of all US states and some of the country's largest public critical infrastructure operators.
Securing Open-Source Software
Anthropic also launched OSS Scanner, an opt-in service inspired by Google's OSS-Fuzz. Enrolled open-source projects receive periodic security scans from Anthropic's most capable models free of charge. Each report includes a proof of concept of how a bug could be exploited, an explanation, and a suggested fix where one is available.
The reports are model-generated and sent without human review, meaning maintainers receive them faster but some will contain inaccuracies such as wrong severity ratings. Anthropic expects a true-positive rate above 90% and plans to improve the rate and fix quality over time. Under Project Glasswing, the company scanned hundreds of widely used open-source projects and privately reported findings to maintainers through coordinated vulnerability disclosure.
Anthropic funded organizations behind widely used open-source code, including the Python Software Foundation, Alpha-Omega, OpenSSF through the Linux Foundation, and the Apache Software Foundation. The Defender Advantage Fund, launched in August, supports pilot programs and keeps OSS Scanner free. Maintainers can also apply to Claude for Open Source for free Claude Max subscriptions.
The Path Ahead
Anthropic said it will bring the Critical Infrastructure Defense Program to more partners and sectors, expand work on open source and the broader supply chain, and share frontier research, tools, and resources. The company forecasts that in two years AI will favor defense, making it easier to catch bugs before they ship and actively defend systems with models, while acknowledging that in the near term verifying, disclosing, and fixing vulnerabilities still depends on people.
Sources: Techmeme
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.