Anthropic has unveiled two interconnected initiatives under its Cyber Mission umbrella. The first, the Critical Infrastructure Defense Program, will deploy the company's most advanced Claude models, engineering talent and security research to organisations protecting power systems, water infrastructure and transport networks. Announced on Thursday, this represents a sustained commitment to bolster the defences of systems that societies depend on.
The second component is OSS Scanner, a no-cost tool that automatically examines open-source code using Anthropic's strongest models and delivers findings directly to project maintainers. Notably, these reports bypass human review before reaching their recipients, though Anthropic has capped its legal liability at $1,000 per incident.
Eleven founding partners
The programme has attracted founding partners spanning consulting firms, cybersecurity vendors and industrial equipment manufacturers. Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation have all signed on. Anthropic characterised these organisations as the trusted advisors and solution providers that infrastructure operators already work with, noting that several are already leveraging Claude to address security vulnerabilities.
The initiative focuses on operational technology—the specialised controllers, software and industrial networks that power manufacturing facilities and often run unchanged for decades. A critical challenge in this domain is that operators frequently cannot shut down these systems for patching, leaving known vulnerabilities exposed indefinitely. Anthropic plans to begin with a limited group of partners to refine its approach.
Critical infrastructure is hard to defend in many ways that AI cannot fix
Anthropic
Hitachi, which established a strategic partnership with Anthropic in May and joined Project Glasswing in June, has committed to participating in the programme's working groups and contributing its operational technology knowledge. However, Anthropic has not disclosed funding arrangements or whether partners receive complimentary access to its models, according to reporting by Axios, which initially broke the story. Questions also remain about how partners will validate fixes without risking disruption to live utilities.
This initiative follows a comparable programme Anthropic launched in June targeting US state, local, tribal and territorial governments. The company reports having provided Claude models and technical assistance to more than half of all US states. In September, OpenAI committed $1 billion toward cybersecurity efforts focused on water utilities and community banks.
Bug reports no human has checked
OSS Scanner operates on an opt-in basis and draws inspiration from Google's OSS-Fuzz initiative. Participating projects receive regular scans from Anthropic's most sophisticated models, including Claude Mythos, as detailed in a post from the Frontier Red Team. Each vulnerability report includes a working demonstration, technical explanation and, where applicable, a proposed fix.
Anthropic anticipates that more than 90 percent of the identified issues will represent genuine vulnerabilities. The company's security researchers validated 97 critical and high-severity findings across 48 projects, with 85 meeting the threshold for its disclosure protocol. An additional 11 represented real issues that duplicated previously known problems, while just one proved to be a false alarm.
During a six-month evaluation period, Anthropic's models identified over 29,000 potential vulnerabilities. The company's team managed to manually review approximately 6,000 of these. Nearly 5,000 unreviewed reports were sent to maintainers who had opted to receive all findings.
Todd Ouska from wolfSSL reported that his project received 74 reports, of which all but two proved valid, with five resulting in CVE designations.
OSS Scanner has helped us find multiple issues in curl worthy of addressing, including one of the worst curl vulnerabilities reported in the last few years
Daniel Stenberg of curl
Anthropic evaluates projects individually and prioritises established codebases with substantial implications for infrastructure and user security. The service agreement explicitly warns that reports may misclassify severity levels or suggest patches that introduce new problems. Maintainers retain responsibility for evaluating every report, and Anthropic's liability remains capped at $1,000. Standard consumer terms also apply to the service.
Attackers ahead for now
Our forecast is that in two years, AI will favor defense
Anthropic
Anthropic acknowledged, however, that this trajectory may not materialise in the immediate future. Presently, the economics favour attackers: exploiting vulnerabilities has become increasingly inexpensive, whereas identifying and remediating them still relies heavily on human expertise. Within Project Glasswing, the interval between discovering a flaw and implementing a fix frequently stretched across months, and in operational environments, fixes can occasionally remain pending for decades.
Last week, Anthropic disclosed that a Chinese-developed model approaches Mythos in capability for cyber exploitation. This week, the company consolidated Glasswing into its broader Cyber Verification Program. The Defender Advantage Fund, established in August, sustains OSS Scanner's free availability.
Anthropic has provided funding to the Python Software Foundation, the Apache Software Foundation, Alpha-Omega and OpenSSF, all operating under the Linux Foundation umbrella. CrowdStrike, one of the newly announced partners, already collaborates with both research labs.
Source: The Next Web



