SafetyPublished Top storyAll news from that day
Ongoing case: Cyber-capable AI models 5 storiesAnthropic launches Cyber Mission with infrastructure program and free scanner
Anthropic announced the Cyber Mission on 8 October, starting with critical infrastructure and open-source software; reports from its free OSS Scanner are sent without human review.
Check our sources · 10 facts from 1 source
Drawn by ai notis from the source: Anthropic
Key points
- Anthropic says the Cyber Mission starts with two areas: critical infrastructure and open-source software.
- The Critical Infrastructure Defense Program's founding partners include Accenture, CrowdStrike, Deloitte, Dragos and Palo Alto Networks, and it brings Claude models and on-site engineers to providers.
- OSS Scanner is opt-in and free; Anthropic says its reports are model-generated and sent without human review, and that it expects a true-positive rate above 90%.
What happened
Anthropic announced the Anthropic Cyber Mission on 8 October 2026, starting with two areas: critical infrastructure and open-source software. The Critical Infrastructure Defense Program gives providers that secure operational technology frontier Claude models, on-site engineers and threat research.
Its eleven founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. OSS Scanner is an opt-in service that gives enrolled open-source projects periodic scans from Anthropic's most capable models, free of charge.
Each report carries a proof of concept, an explanation and a suggested fix where one is available. The reports are model-generated and sent without human review, and Anthropic says it expects a true-positive rate above 90%.
Anthropic also says it merged Project Glasswing into its expanded Cyber Verification Program earlier in the week.
What it means for you
Our viewOSS Scanner and the infrastructure program are Anthropic's own offers, and the accuracy figure is an expectation, not a measured result. Anthropic itself says the scanner's reports are sent without human review and some will contain inaccuracies, such as a wrong severity rating.
For maintainers that means a free source of findings that still needs a person to confirm each report before acting on it.
If you maintain open-source code or run operational technology, check what enrolling would send to Anthropic, who will triage the reports, and whether your existing vulnerability disclosure process can absorb them.
It adds no new facts.
Your reaction
We count reactions per story and day, never who reacted. The counts help us choose what goes in the monthly issue. If you are signed in, your own page shows yours too.
Check our sources
Every sentence above is checked against this source.
1 Anthropic Cyber Mission
Open the source archived copy-
Anthropic published the post introducing the Anthropic Cyber Mission on 8 October 2026.
citeOct 8, 2026 ... Today we're launching the Anthropic Cyber Mission, a long-term commitment to securing the systems everyone depends on.
-
Anthropic says the Cyber Mission starts with two areas: critical infrastructure, and open-source software.
citeWe're starting with two areas: Critical infrastructure ... [and open-source software]
-
The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers and Anthropic's threat research to providers that protect operational technology.
citeToday, we're introducing the Critical Infrastructure Defense Program (CIDP), which brings frontier models, on-site engineers, and threat research to the defenders that protect operational technology.
-
The program's founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
citeIts founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
-
OSS Scanner is an opt-in service that gives enrolled open-source projects periodic scans from Anthropic's most capable models, free of charge.
citewe're launching OSS Scanner, an opt-in service inspired by Google's OSS-Fuzz. Enrolled projects receive periodic scans from our most capable models, free of charge.
-
Each OSS Scanner report includes a proof of concept of how the bug could be exploited, an explanation, and a suggested fix where one is available.
citeEach report includes a proof of concept of how the bug could be exploited, an explanation, and a suggested fix where one is available.
-
Anthropic says OSS Scanner reports are model-generated and sent without human review, so some will contain inaccuracies such as a wrong severity rating.
citeThe reports are model-generated and sent without human review. That means maintainers receive them faster, but it also means that some will contain inaccuracies, such as a wrong severity rating.
-
Anthropic says it expects an OSS Scanner true-positive rate above 90%.
citeWe expect a true-positive rate above 90%, and will work to improve the true positive rate and fix quality over time.
-
Anthropic says that earlier in the week it merged Project Glasswing into its expanded Cyber Verification Program.
citeEarlier this week, we merged Project Glasswing into our expanded Cyber Verification Program, which gives many more defenders access to our most capable models.
-
Anthropic says its Defender Advantage Fund (0xDAF), launched in August, supports pilot programs and keeps OSS Scanner free.
citeThe Defender Advantage Fund (0xDAF), which we launched in August, supports pilot programs in these areas and keeps OSS Scanner free.
Topics
The morning email
On the mornings we publish: the three top stories and up to four short ones. Free.
We email you a link to confirm. An issue may include one sponsor, always labelled Sponsored · Advertisement. Our emails count opens and clicks, not who made them. Unsubscribe in one click. What we keep