Advisory
Published 2026-10-08
Verified 2026-10-09

Anthropic launches Cyber Mission: Critical Infrastructure Defense Program with 11 OT/security partners and free opt-in OSS Scanner sending unreviewed model-generated bug reports to open-source maintainers

On 8 October 2026 Anthropic announced the Anthropic Cyber Mission, which it describes as a long-term effort to give defenders tools, research and funding, starting with critical infrastructure and open-source software. The Critical Infrastructure Defense Program puts frontier Claude models, on-site Anthropic engineers and threat research with trusted providers that secure operational technology (power, water, factories, transport). Founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation; Anthropic says it is starting with a small cohort. OSS Scanner is an opt-in service, modelled on Google's OSS-Fuzz, that periodically scans enrolled open-source projects free of charge. Each report includes a proof of concept, an explanation and a suggested fix where available; reports are model-generated and sent without human review, so some will be wrong (for example severity), and Anthropic says it expects a true-positive rate above 90%. Anthropic also cites funding for the Python Software Foundation, Alpha-Omega and OpenSSF (Linux Foundation) and the Apache Software Foundation, and says the Defender Advantage Fund keeps OSS Scanner free. It builds on the Project Glasswing lesson that finding bugs is now easy but verifying, prioritising and fixing them is slow. Distinct from the desk card on the expanded Cyber Verification Program tiers (anthropic-cvp-tiers-20261006). Primary: Anthropic; wire: Cyber Security News.

Product
Anthropic Cyber Mission — Critical Infrastructure Defense Program; OSS Scanner (opt-in open-source scanning)
Versions
n/a — program launch, not a product vulnerability
Exploited in Australia?
unknown
Patch to
Open-source maintainers: enrol in OSS Scanner only if you have triage capacity, and verify every model-generated report and severity before acting or publishing. OT operators: ask your OT security provider whether it is in the program and how AI-found issues are validated before changes reach running plant. Treat AI-found bug volume as a triage and patch-capacity problem, not just a discovery win.

Primary: Anthropic — Introducing the Anthropic Cyber Mission (8 Oct 2026) · Vendor: Anthropic announcement (Critical Infrastructure Defense Program and OSS Scanner) · Cyber Security News — Anthropic Cyber Mission to support defenders with tools, research and resources (9 Oct 2026)

ai ot ics