Anthropic launches Cyber Mission with infrastructure program and unreviewed OSS scans
Anthropic's new Cyber Mission pairs an 11-company critical-infrastructure program with a free opt-in scanner that sends model-generated vulnerability reports to open-source maintainers without human review.
Anthropic launched the Cyber Mission on October 8 with two operating programs: a partnership for critical-infrastructure defenders and a free service that scans eligible open-source projects for vulnerabilities.
The Critical Infrastructure Defense Program, or CIDP, will provide Claude models, Anthropic engineers working on site and company threat research to security providers serving power grids, water systems, factories, transportation networks and government systems. The separate OSS Scanner will periodically send participating maintainers model-generated findings without human review or triage, leaving maintainers to determine whether the reports and severity assessments are correct.
Anthropic named 11 founding CIDP partners: Accenture, Booz Allen Hamilton, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. CrowdStrike, Dragos, Booz Allen and Nozomi Networks each issued a same-day announcement confirming participation. Anthropic said several partners are already using Claude to fix vulnerabilities and help customers do the same, but its launch did not identify the partners, customers, flaws or results.
The partner announcements describe a collaboration framework rather than measured security outcomes. CrowdStrike said it will receive Anthropic technical guidance and research access. Dragos plans to turn program lessons into detections and engineering guidance, Booz Allen said partners will pursue joint research, and Nozomi described a forum for applying Claude and exchanging operational lessons. Nozomi also said people remain responsible for decisions and actions in operational environments.
OSS Scanner is available on an opt-in basis to projects Anthropic deems eligible. A core maintainer applies by opening a pull request in the public scanner repository with configuration and build instructions. The repository says the scanner builds each project in an isolated environment and performs the security audit without internet access. Anthropic says selection is made case by case using criteria similar to OSS-Fuzz, including whether a project has a critical impact on infrastructure and user security.
The service’s speed comes with a stated limitation. Its reports go directly to enrolled maintainers without a person first checking the underlying finding. Anthropic warns that a report can be invalid, inaccurate or assigned the wrong severity. Reports can include reproduction material, a root-cause explanation and a proposed patch where one is available.
Anthropic says it expects more than 90% of the service’s findings to be true positives, but that is a company projection rather than an independently audited result. In an internal evaluation of an early scanner version, expert penetration testers reviewed 97 findings rated high or critical: Anthropic said 85 met its disclosure threshold, 11 were real but duplicated known issues or other scan results, and one was invalid.
Anthropic’s scanner repository says unvalidated scanner reports have no 90-day disclosure deadline and will not be made public. Projects that do not opt in to raw model reports can continue to receive human-verified disclosures through Anthropic’s existing coordinated-disclosure process.
More news

Anthropic Expands Cyber Verification Program Into Three Access Tiers

Hacktron says Claude helped breach OpenAI employee accounts

Anthropic says it disrupted Claude misuse across cyberattacks and weapons research
