AI Frontier Post
AI News

Anthropic launches the Cyber Mission: on-site engineers for critical infrastructure, free AI scans for open source

Anthropic on Thursday launched the Anthropic Cyber Mission, a long-term push to aim frontier AI at cybersecurity's least-resourced defenders: the operators of power grids and water systems get the Critical Infrastructure Defense Program with 11 founding partners, while open-source projects get OSS Scanner — free, AI-powered vulnerability scans with proof-of-concept exploits attached.

Anthropic turned its own security research into a product line on Thursday: the company launched the Anthropic Cyber Mission, a long-term effort to put frontier models, on-site engineers, and threat research in the hands of the people defending the systems everyone depends on. It opens with two programs — a Critical Infrastructure Defense Program with eleven founding partners, and a free AI-powered vulnerability scanner for open-source projects.

The framing is deliberate. Anthropic said frontier models can be misused to exploit vulnerabilities and conduct cyber operations, and that state-sponsored adversaries have spent years establishing footholds across sectors. The defenders of critical infrastructure and open-source software have decades of security experience, it said, but severe resource shortages — so the Cyber Mission deploys engineering talent, tools, and funding to their side of the ledger.

The Critical Infrastructure Defense Program

The CIDP brings frontier Claude models, on-site engineers, and Anthropic's threat research to the companies that operators of power grids, water systems, and transportation networks rely on to keep systems secure — starting with the operational technology behind those systems, plus government networks.

The eleven founding partners are the ones operators already call when deciding which fixes are safe to apply to a running system, according to SiliconANGLE: from consulting, Accenture, Booz Allen, Deloitte, and PwC; from security vendors, CrowdStrike, Palo Alto Networks, and the industrial specialists Dragos, Insane Cyber, and Nozomi Networks; and from the hardware itself, Hitachi and Rockwell Automation.

A security operations center with analysts monitoring threat dashboards.
A security operations center. The Cyber Mission targets the resource gap between attackers and the defenders of critical systems. Image: TechDay.

The operational-technology focus matters because this is the hardest ground in cybersecurity: equipment built to run for decades often cannot be taken offline for a patch, so known flaws can sit exposed for years. Andrew Turner, president of commercial cyber at Booz Allen, called operational technology "the next frontier for autonomous AI-enabled attacks" in comments published with the announcement — and said what matters now is how much control AI can gain over an industrial process, and how fast.

One open question hangs over the program: the commercial terms. Axios noted Anthropic has not said whether partners get free model access or who covers the computing costs, or how partners will test and deploy fixes without disrupting utility operations.

OSS Scanner: free AI security audits for open source

The open-source half of the launch is the more radical move. OSS Scanner is a free, opt-in service that runs regular security scans of enrolled open-source projects with Anthropic's strongest models — and every report goes straight to maintainers with a proof of concept and a suggested fix, without human review in between. Speed is the point: Google's OSS-Fuzz, which runs fuzzers against open-source code, inspired the setup.

The numbers from early trials are striking. Anthropic's models turned up more than 29,000 candidate vulnerabilities in widely used software over the past six months; expert penetration testers who vet the company's coordinated disclosures checked 97 critical and high-severity findings across 48 projects and cleared 85 for disclosure. Embedded encryption library wolfSSL said all but two of the 74 reports it received during early trials were valid — and five became CVEs. Early tester Anton Arapov of the OpenSSL Corporation said a report with a real exploit attached is "basically job done for an engineer."

An industrial control room with operators monitoring infrastructure systems.
Control rooms like this sit atop operational technology that often can't be patched without downtime — the core problem the Cyber Mission's infrastructure program targets. Image: Design Informatics.

Eligibility follows the OSS-Fuzz test of "critical impact on infrastructure and user security," with decisions made case by case, and core maintainers can enroll by submitting a pull request to an Anthropic GitHub repository. The Defender Advantage Fund that Anthropic set up in August pays to keep the scanner free; the company has also funded the Python Software Foundation, the Apache Software Foundation, and the Alpha-Omega and OpenSSF efforts through the Linux Foundation.

What to actually watch

Both launches draw on the lessons of Project Glasswing, which gave vetted organizations access to Claude Mythos from April until it was folded into an expanded Cyber Verification Program earlier this week. Anthropic's own verdict on that experiment: finding vulnerabilities has never been easier; verifying, prioritizing, and fixing them remains hard — and Glasswing has not yet cut cyber risk by enough.

That tension is the whole bet of the Cyber Mission. Anthropic expects AI to favor defenders within two years; for now, the cost of exploiting a flaw keeps falling while the cost of verifying and repairing one is still slow, human work. Shipping exploit-carrying reports straight to maintainers — no human in the loop — is the company's answer to the asymmetry. If OSS Scanner's hit rate holds at scale, it becomes one of the most consequential deployments of frontier AI in software security to date. If it doesn't, Anthropic just volunteered to find out in public.