Anthropic launches Cyber Mission to secure critical infrastructure and open-source software
Key point
The initiative introduces the Critical Infrastructure Defense Program with 11 founding partners and a free OSS Scanner service for vulnerability detection.
Details
Anthropic has launched the Anthropic Cyber Mission, a long-term effort to support defenders with tools, research, and resources for securing software and systems. The mission addresses the growing threat of state-sponsored adversaries exploiting vulnerabilities in critical infrastructure and open-source code, areas where defenders face severe resource shortages despite decades of experience.
Critical Infrastructure Defense Program
The mission begins with the Critical Infrastructure Defense Program (CIDP), which provides frontier Claude models, on-site engineers, and threat research to trusted providers securing operational technology (OT). Founding partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. These organizations will use AI to identify and repair weaknesses in power grids, water systems, and transportation networks, where traditional patching is often impossible due to the risk of taking systems offline.
OSS Scanner for Open-Source Security
Anthropic also launched OSS Scanner, an opt-in service that offers free, periodic security scans from its most capable models to open-source projects. Inspired by Google’s OSS-Fuzz, the service provides reports with proof-of-concept exploits, explanations, and suggested fixes. While reports are model-generated without human review to ensure speed, Anthropic expects a true-positive rate above 90% and aims to improve accuracy over time. This builds on Project Glasswing, which scanned hundreds of projects and highlighted the need for faster verification and patching workflows.
Strategic Goals and Future Outlook
The Cyber Mission aims to shift the balance of power in cybersecurity, with Anthropic forecasting that AI will favor defense within two years by making it easier to catch bugs and write secure software. In the near term, the focus is on accelerating the fix cycle, which currently lags behind the speed of AI-driven exploitation. The initiative also expands access to the Cyber Verification Program and continues funding for organizations like the Python Software Foundation and OpenSSF to support the broader open-source ecosystem.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.