top of page

Anthropic launches OSS Scanner and Cyber Mission to protect critical infrastructure and open-source software

9 minutes ago
9 min read
Anthropic launches OSS Scanner and Cyber Mission to protect critical infrastructure and open-source software - Data Studios

Anthropic announced the Anthropic Cyber Mission on October 8, 2026, introducing two cybersecurity initiatives designed to protect widely used open-source software and the industrial systems supporting essential services.


The initiative combines OSS Scanner, a free AI-powered vulnerability detection service for eligible open-source projects, with the Critical Infrastructure Defense Program (CIDP), which provides advanced Claude models, engineering expertise, and threat research to organizations protecting energy networks, water systems, transportation infrastructure, and industrial facilities.


The announcement follows Project Glasswing, Anthropic's earlier cybersecurity initiative that demonstrated how frontier AI models could identify large numbers of previously undetected software vulnerabilities. That experience also exposed a practical limitation: vulnerability discovery is accelerating faster than the human processes required to validate findings, prioritize remediation, and deploy reliable corrections.


Anthropic's new programs address different parts of this problem. OSS Scanner makes automated security research available to open-source maintainers, while CIDP brings AI capabilities into industrial environments where security weaknesses can have physical and operational consequences.


··········


OSS SCANNER PROVIDES FREE AI-POWERED SECURITY AUDITS FOR OPEN-SOURCE SOFTWARE.


The service delivers recurring vulnerability assessments using Anthropic's strongest models, including Claude Mythos, without requiring maintainers to pay for the scanning infrastructure.


OSS Scanner is an opt-in service designed for established open-source projects whose software is important to digital infrastructure or user security.


Unlike traditional security auditing services, which generally require organizations to purchase scanning tools or allocate specialist engineering resources, OSS Scanner covers the computational cost of conducting advanced AI-assisted vulnerability research.


Its scanning pipeline uses AI agents to examine source code, investigate potential security weaknesses, reproduce suspicious behavior, analyze underlying causes, and generate candidate patches.


Each report can include a technical explanation of the vulnerability, a reproducible demonstration of the issue, supporting analysis, and a proposed correction when available.


The principal operational difference concerns human verification. OSS Scanner sends findings generated by its AI pipeline directly to participating maintainers without requiring Anthropic's security researchers to review every report beforehand.


This arrangement reduces the delay between discovering a potential vulnerability and informing the developers responsible for correcting it. However, it also transfers more responsibility for evaluating the findings to the receiving project.


Reports may contain incorrect severity classifications, duplicate findings, or vulnerabilities that are not exploitable under the project's actual security conditions.


Anthropic expects the service to achieve a true-positive rate above 90%, although this remains a company expectation rather than a demonstrated accuracy rate across every participating project.


OSS Scanner does not automatically deploy patches or modify production software. Maintainers retain responsibility for validating findings, reviewing proposed corrections, and integrating approved changes into their existing development processes.


··········


HOW OSS SCANNER WORKS AND HOW DEVELOPERS CAN ACCESS THE SERVICE.


Participation requires an approved project configuration, a reproducible build environment, and an authorized maintainer capable of receiving and evaluating vulnerability reports.


Core maintainers can request enrollment by submitting a pull request to Anthropic's OSS Scanner repository on GitHub.


The configuration is stored in a project-specific YAML file and provides the information necessary to retrieve, build, and analyze the software.


The principal requirements include:


  • Repository configuration: Identification of the source code repository and relevant branch.

  • Security contact: An email address for the maintainer responsible for receiving vulnerability reports.

  • Docker environment: A reproducible build configuration containing the dependencies needed for automated testing.

  • Maintainer verification: Confirmation that the applicant is authorized to enroll the project.

  • Optional threat model: Documentation describing attack surfaces, security boundaries, severity criteria, and reporting preferences.

  • Optional encryption: A GPG public key for receiving encrypted vulnerability reports.


Anthropic evaluates applications individually, prioritizing established projects that have substantial security relevance, significant downstream adoption, or exposure to remotely supplied inputs.


The Docker-based environment is particularly important because scanning agents operate inside hardened sandboxes without internet access after the build stage. Dependencies can be downloaded while preparing the environment, but the subsequent security analysis runs offline.


This arrangement limits the network access available to the agents while allowing them to execute tests and investigate vulnerabilities in controlled conditions.


After enrollment, the service performs an initial assessment and subsequently conducts recurring scans. The frequency is not guaranteed and may vary depending on available scanning capacity and the number of participating projects.


Reports are delivered by email, and maintainers can temporarily disable automated notifications or withdraw their projects.


Anthropic also maintains a conventional coordinated vulnerability disclosure process for projects that prefer findings to undergo human verification before delivery.


Importantly, unvalidated OSS Scanner reports do not automatically trigger a 90-day public disclosure deadline. If Anthropic subsequently verifies a vulnerability through its established disclosure process, the corresponding disclosure rules may apply.


··········


EARLY TESTING IDENTIFIED THOUSANDS OF POTENTIAL VULNERABILITIES WITH STRONG RESULTS IN A SELECTED SAMPLE.


Anthropic's reported results illustrate both the technical capabilities of AI-assisted vulnerability detection and the increasing workload created by large-scale automated scanning.


During approximately six months of security research, Anthropic's systems identified more than 29,000 candidate vulnerabilities across important software projects.


Its researchers manually reviewed and triaged approximately 6,000 reports, while nearly 5,000 additional reports were sent directly to maintainers who requested access to unverified findings.


Using the rounded figures disclosed by Anthropic, the volume manually reviewed represented approximately 21% of the candidate findings.


That percentage measures the capacity of the manual review process relative to discovery volume. It does not indicate the proportion of genuine vulnerabilities or the percentage successfully corrected.


To evaluate an early version of OSS Scanner, Anthropic's penetration-testing specialists examined 97 findings initially classified as critical or high severity across 48 projects.


........


Evaluation metric

Reported result

Candidate vulnerabilities identified during broader scanning

More than 29,000

Reports manually reviewed and triaged

Approximately 6,000

Reports delivered directly at maintainers' request

Nearly 5,000

High- and critical-severity findings selected for evaluation

97

Findings meeting disclosure validation standards

85

Genuine findings duplicating known or other reported issues

11

Invalid findings

1

Findings meeting validation standards within the evaluated sample

87.6%


........


The evaluation found that 85 of the 97 selected findings met Anthropic's coordinated vulnerability disclosure standards. Eleven additional findings concerned genuine issues but duplicated known vulnerabilities or other reports, while one was classified as invalid.


These results suggest that the scanner can generate technically useful reports, particularly for serious vulnerabilities. However, the sample consisted of findings already classified as high or critical severity, so its performance cannot automatically be generalized to the entire population of generated reports.


Several established open-source projects participated in early testing, including PostgreSQL, OpenSSL, wolfSSL, and HotCRP.


The wolfSSL team reported that 72 of 74 findings it received were valid, with five subsequently assigned CVE identifiers.


Feedback from participating maintainers also indicated that some proposed patches were sufficiently developed to be incorporated with relatively limited modifications.


Nevertheless, vulnerability discovery and vulnerability remediation remain separate outcomes.


A technically valid report may require additional investigation to establish exploitability, identify affected versions, assess downstream dependencies, and determine whether a proposed patch introduces compatibility or reliability problems.


For smaller open-source projects, the availability of free scanning therefore reduces one category of security expenditure while potentially increasing the engineering workload associated with validation and remediation.


··········


THE CRITICAL INFRASTRUCTURE DEFENSE PROGRAM BRINGS CLAUDE INTO INDUSTRIAL CYBERSECURITY.


Anthropic's second initiative focuses on operational technology environments, where security incidents can interrupt essential services and software changes must satisfy strict reliability requirements.


The Critical Infrastructure Defense Program supports organizations responsible for securing operational technology (OT) and industrial control systems (ICS).


These environments include industrial controllers, supervisory control and data acquisition systems, specialized communication networks, and equipment used to operate physical infrastructure.


Unlike conventional enterprise applications, industrial systems frequently depend on proprietary technologies, long equipment lifecycles, and maintenance procedures designed to minimize operational interruptions.


Some controllers remain in service for decades, while deploying a security update may require scheduled downtime, extensive compatibility testing, or coordination with equipment manufacturers.


Anthropic intends to support these environments by providing frontier Claude models, on-site engineering assistance, and cybersecurity research to specialized organizations already serving critical infrastructure operators.


The program begins with 11 founding partners.


........


Founding partner

Relevant cybersecurity or infrastructure expertise

Accenture

Industrial cybersecurity and technology consulting

Booz Allen

Government and critical infrastructure security

CrowdStrike

Threat intelligence and endpoint protection

Deloitte

Cybersecurity consulting and operational risk

Dragos

Industrial threat detection and OT security

Hitachi

Industrial systems and infrastructure technology

Insane Cyber

Industrial security monitoring

Nozomi Networks

OT, IoT, and industrial network security

Palo Alto Networks

Network security and threat intelligence

PwC

Cybersecurity consulting and industrial risk

Rockwell Automation

Industrial automation and control systems


........


The partner structure connects three capabilities that are often separated in industrial cybersecurity: advanced vulnerability research, specialized knowledge of operational environments, and the engineering authority required to implement corrections safely.


For example, AI-assisted analysis may identify a weakness in the software controlling industrial equipment, but addressing it can require a vendor-approved firmware update, a network configuration change, or temporary isolation of a component.


An effective remediation plan must therefore account for physical dependencies, operational continuity, and safety requirements rather than relying exclusively on conventional software vulnerability scores.


Several founding partners are already using Claude to investigate and address vulnerabilities.


However, Anthropic has not demonstrated that its models can autonomously secure industrial facilities or safely implement corrections without specialist oversight.


The company's approach consequently emphasizes cooperation with established providers rather than replacing the engineers and security teams responsible for operating these systems.


Beyond CIDP, Anthropic also reports having provided advanced Claude capabilities and technical assistance to more than half of US states through an earlier government-focused cyber defense initiative.


··········


PROJECT GLASSWING AND THE EXPANDED CYBER VERIFICATION PROGRAM PROVIDE THE TECHNICAL FOUNDATION.


The Cyber Mission builds on previous efforts to give qualified defenders access to increasingly capable AI models while restricting their potential misuse.


Project Glasswing, announced in April 2026, brought together Anthropic and major technology organizations to evaluate the defensive applications of advanced Claude models, particularly Claude Mythos.


The initiative focused on identifying vulnerabilities in foundational software, operating systems, enterprise infrastructure, and widely deployed open-source components.


According to figures disclosed by Anthropic on October 6, participating organizations identified at least 129,000 verified software vulnerabilities between April and July 2026.


Anthropic separately reported approximately 5,500 additional verified vulnerabilities discovered through its own open-source scanning activities between April and October.


Across these efforts, more than 33,000 verified findings were classified as high or critical severity.


These numbers refer to identified and verified vulnerabilities, rather than an equivalent number of completed patches or systems successfully secured.


On October 6, Anthropic also expanded its Cyber Verification Program, incorporating Project Glasswing into a broader access framework for qualified cybersecurity professionals.


The updated program includes three access levels:


  • Defense Access: Supports defensive security operations, incident response, malware analysis, and vulnerability assessment.

  • Red Team Access: Extends permitted activities to authorized penetration testing and adversarial security evaluations.

  • Specialized Access: Provides more extensive capabilities to a limited group of verified organizations conducting sensitive security assessments.


The program makes advanced models available under different verification requirements and security controls, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1.


This structure reflects the dual-use character of advanced cybersecurity models.


The same capabilities that allow a defender to discover a previously unknown weakness can potentially assist an attacker in identifying exploitable systems or developing more sophisticated attacks.


Anthropic's access controls therefore distinguish between ordinary defensive analysis, authorized adversarial testing, and particularly sensitive security research.


OSS Scanner and CIDP operate within this broader strategy by directing advanced model capabilities toward software maintainers and established infrastructure security providers.


··········


THE LONG-TERM IMPACT WILL DEPEND ON VERIFIED PATCHES, DEPLOYMENT SPEED, AND OPERATIONAL RESILIENCE.


The effectiveness of Anthropic's Cyber Mission will ultimately depend on whether faster vulnerability discovery produces measurable reductions in exploitable weaknesses.


The two initiatives address different economic and operational constraints.


In open-source development, security work is frequently performed by small teams whose software may support thousands of commercial products and public services.


OSS Scanner reduces the direct cost of advanced vulnerability discovery, potentially allowing maintainers to investigate weaknesses that would otherwise remain undetected.


However, it does not eliminate the labor required to validate reports, develop corrections, test compatibility, and distribute updated versions.


For critical infrastructure, the challenge extends beyond software engineering.


Industrial operators may need to coordinate security changes with equipment suppliers, regulatory requirements, maintenance schedules, and operational safety procedures.


Consequently, a substantial increase in detected vulnerabilities does not necessarily translate into an equally rapid reduction in cyber risk.


Three operational measures will be particularly useful for evaluating the Cyber Mission: the proportion of reported vulnerabilities that are independently validated, the proportion subsequently corrected, and the time required for those corrections to reach affected systems.


Additional indicators, including repeat vulnerabilities, patch-related incidents, and changes in exposure to known attack paths, would provide a more complete assessment of defensive effectiveness.


Anthropic has indicated that future work will include automated vulnerability triage, improved patch generation, and research into software architectures that reduce the likelihood of security defects.


Those developments could improve remediation capacity, but their effectiveness will need to be demonstrated across diverse software projects and industrial environments.


The company also expects advanced AI to eventually favor cybersecurity defenders by making vulnerabilities easier to discover and secure software easier to develop. That remains a forecast rather than an established outcome, especially as attackers gain access to increasingly capable models.


The October 8 announcement nevertheless establishes a concrete expansion of Anthropic's cybersecurity activities: a funded scanning service for essential open-source software and an industrial defense program involving established technology and security providers.


Their success will be determined less by the number of vulnerabilities AI systems can discover than by the ability of maintainers, vendors, and infrastructure operators to convert those discoveries into reliable corrections before vulnerabilities are exploited.


··········


FOLLOW US FOR MORE.


DATA STUDIOS


datastudios.org

bottom of page