Cybersecurity

Anthropic Launches Cyber Mission to Protect Infrastructure and Open-Source Software

Anthropic announced a long-term initiative to support cybersecurity defenders, including a program to protect operational technologies in the energy, water, and transportation sectors, and a free service for scanning open-source software projects using Claude models.

2026-10-08
4 min read
11 views
certi.news Editorial Team
Anthropic Launches Cyber Mission to Protect Infrastructure and Open-Source Software

On October 8, 2026, Anthropic launched what it calls the “Anthropic Cyber Mission,” a long-term commitment to providing tools, research, and resources to help defenders secure the systems on which essential services depend. The initiative begins with two pillars: protecting critical infrastructure and scanning open-source software for vulnerabilities.

A Program Dedicated to Operational Technology

The launch includes the Critical Infrastructure Defense Program (CIDP), which combines advanced Claude models with field engineers and threat research to help organizations securing the operational technology behind power grids, water systems, and transportation networks, in addition to government systems.

Anthropic says these environments rely on industrial controllers, software, and networks designed to operate for decades, and they often cannot be taken offline to install a security patch. As a result, known vulnerabilities may remain unaddressed for years, while an unsafe change could disrupt an industrial facility. In its first phase, the program includes partners such as Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.

Some partners have already begun using Claude to address vulnerabilities and help their customers carry out the same work. Anthropic will begin with a limited group of service providers to test the most practical and effective approaches, with the program later expanding to additional partners and sectors.

Free Scanning for Open-Source Projects

The company also launched OSS Scanner, an optional service that provides free periodic scans of open-source projects using its most powerful models. Each report includes a proof of concept showing how to exploit the flaw, an explanation of it, and a proposed fix when available.

The reports are generated automatically and are not subject to human review before being sent to maintainers. Anthropic says it expects a true-positive rate of more than 90%, but warns that errors may occur, such as an inaccurate assessment of a vulnerability’s severity. The service targets projects that have the capacity to triage and follow up on the results; for projects that require human review, the company will continue sharing human-verified disclosures through its Coordinated Vulnerability Disclosure Policy.

What Changes in Practice?

The initiative follows “Project Glasswing,” which scanned hundreds of widely used projects and uncovered vulnerabilities reported to maintainers. Anthropic acknowledges that finding vulnerabilities has become easier, but validating, prioritizing, and fixing them remains slow, and months may pass between discovering a problem and addressing it. In operational technology, patching may be delayed until it can be safely applied to equipment in operation, and in rare cases the wait may extend for decades.

Therefore, the launch does not present artificial intelligence as a substitute for the expertise of infrastructure operators or security review. OSS Scanner accelerates access to findings but places the responsibility for verification on maintainers, while deploying patches in industrial environments remains constrained by safety and continuity requirements. Anthropic also expects that achieving a tangible impact will require years of learning and cooperation between the public and private sectors.

Expansion Plans

Anthropic plans to expand its tools to accelerate vulnerability triage and remediation, research more secure software architectures and practices, and support more software projects and supply chains. Its other programs, including the Cyber Verification Program and Claude for Open Source, also provide broader access to Claude’s defensive capabilities or free subscriptions for some eligible maintainers and teams.

News source
Anthropic Newsroom
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news