×

Anthropic Launches Critical Infrastructure and Open Source Cyber ​​Mission – Unite.AI

Anthropic Launches Critical Infrastructure and Open Source Cyber ​​Mission – Unite.AI

Anthropic announced the Anthropic Cyber ​​Mission on October 8, 2026, describing it as a long-term effort to help protect the systems the public relies on. The initiative begins with two programs: a critical infrastructure defense program supported by 11 founding partners and OSS Scanner, a free opt-in service that performs regular security scans of open source software with the company’s most powerful models.

Anthropic argues that frontier models can be misused to exploit vulnerabilities and conduct cyber operations, and that state-sponsored adversaries have spent years establishing footholds in many sectors so they can destroy such systems. Defenders of critical infrastructure and the open source community, the company said, have decades of security experience but face severe resource shortages, and the Cyber ​​Mission will deploy engineering talent, tools and funding to support them.

Critical Infrastructure Defense Program

The Critical Infrastructure Defense Program provides frontier Claude models, on-site engineers and Anthropic threat research to trusted vendors defending operational technology, starting with the systems behind power grids, water systems and transportation networks, along with government systems. Its founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

Anthropic described the group as made up of consulting and advanced technology firms that manage security programs, security companies that watch over corporate and industrial networks, and manufacturers that build and repair the equipment itself. Several partners are already working with Claude to patch vulnerabilities and help customers do the same, the company said, and the first step is working with a small group of vendors to learn which strategies are most effective and practical. Companies that make security products or services for critical infrastructure may see interest as the program expands.

In statements released with the announcement, CrowdStrike said that “critical infrastructures facing machine-speed threats require machine-speed defense,” and Palo Alto Networks said it is pairing Unit 42’s threat intelligence and operational expertise with Anthropic’s frontier models to help operators defend essential services. Booz Allen has called operational technology the next frontier in AI-based autonomous attacks.

Operational Technology and Government Systems

Power grids, water utilities, factories and transportation networks run on controllers, control software and industrial networks that are built to last for decades and often cannot be taken offline for repair, so known vulnerabilities can remain unpatched for years. Anthropic called this work specialized, noting that the equipment is proprietary, that changes come with risks, and that a single mistake can destroy a facility, leaving operators dependent on a small group of trusted suppliers. The company said it believes frontier models can help find and fix weak spots before they are used to knock out electricity or make water unsafe, while acknowledging that critical infrastructure is difficult to defend in many ways that artificial intelligence cannot fix.

The program extends Anthropic’s work into the government sector. In June, the company launched a cyber defense program for state, local, tribal and territorial governments; Anthropic said it has offered frontier Claude models and technical support to more than half of all U.S. states and some of the country’s largest public critical infrastructure operators, accelerating code scanning and patching, incident response, red teaming and other security workflows.

OSS scanner for open source projects

The second program, OSS Scanner, is an opt-in service inspired by Google’s OSS-Fuzz that provides subscribed open source projects with periodic scans of Anthropic’s most capable models, including Claude Mythos, at no cost. According to a Frontier Red Team post published the same day, each report contains a standalone player or proof of concept, an explanation with a bisection where possible, and a patch candidate when available. Reports are completely template-generated and sent without human review, which Anthropic says allows for faster delivery but means some will contain inaccuracies such as an incorrect severity rating; the company expects a true positive rate above 90%.

To validate an initial release, Anthropic asked expert penetration testers who review coordinated vulnerability disclosure findings to test 97 critical, high-severity scanner findings across 48 projects. The team reported that 85 (88%) met the disclosure process requirements, that 11 of the remainder were real but duplicated known problems or other findings, and that one was a false positive. Over the past six months, the company said, its models reported more than 29,000 candidate vulnerabilities, about 6,000 of which were manually reviewed and scored, while nearly 5,000 unverified reports went directly to maintainers who asked to receive everything.

The maintainers mentioned in the post reported excellent results. Todd Ouska of wolfSSL said that “of the 74 reports we received, all but two were valid and five became CVEs.” Noah Misch of PostgreSQL said that an unusually high fraction of the scanner results discovered PostgreSQL flaws, and that several reports came with fixes that his team could use almost as-is, while Anton Arapov of OpenSSL Corporation said that the reports his organization received, including raw model output, were as good or better than the ones he gets from people. HotCRP’s Eddie Kohler described the bug reports as thorough and clear.

Lead maintainers of eligible projects sign up by submitting a pull request to Anthropic’s oss-scanner GitHub repository, with eligibility based on criteria similar to OSS-Fuzz, including critical infrastructure and user security impact, decided on a case-by-case basis. Anthropic said projects without the ability to evaluate results will continue to receive human-verified disclosures under its coordinated vulnerability disclosure policy, and distinguished OSS Scanner from Claude Security, its general access enterprise code scanning and patching product. Maintainers can also turn to Claude for Open Source for free subscriptions to Claude Max and the Cyber ​​Verification Program for expanded access.

Glasswing project and next steps

Anthropic said the new efforts build on lessons from Project Glasswing, announced April 7, 2026 with Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks. As part of that initiative, Anthropic has committed up to $100 million in credits for using Claude Mythos Preview and $4 million in direct donations to open source security organizations, and said it has donated $2.5 million to Alpha-Omega and OpenSSF through the Linux Foundation and $1.5 million to the Apache Software Foundation. On October 6, 2026, Anthropic launched an expanded cyber verification program with three levels of access, and the Cyber ​​Mission announcement stated that Project Glasswing was incorporated into that program, with existing Glasswing members moving up to the specialized access level.

Anthropic said it also funded the Python Software Foundation and supports Akrites and Gold Eagle, which collect and coordinate vulnerability reports from many sources so maintainers aren’t overwhelmed. The Defender Advantage Fund, launched in August, supports pilot programs in these areas and keeps OSS Scanner free.

Anthropic’s prediction is that within two years, AI will power defense, making it easier to spot bugs before they ship and actively defend systems with models, although the company said this may not hold in the near term. He said that at Glasswing, months often passed between the discovery and fixing of a vulnerability, and that with operational technology a fix can in rare cases take decades to securely apply. In the coming months, Anthropic said, it will bring the Critical Infrastructure Defense Program to more partners and industries, share what it learns, including what didn’t work, expand its open source and supply chain work, and collaborate with other AI developers, security companies and governments pursuing initiatives of their own.

Post Comment