Anthropic Cyber Mission: free scans for open-source code
Anthropic launched the Anthropic Cyber Mission on October 8, 2026, a long-term effort to help defenders secure critical infrastructure and open-source software. It starts with two programs. OSS Scanner gives open-source
Anthropic launched the Anthropic Cyber Mission on October 8, 2026, a long-term effort to help defenders secure critical infrastructure and open-source software. It starts with two programs. OSS Scanner gives open-source projects free, regular vulnerability scans from Anthropic's strongest models. A second program puts Claude models and Anthropic engineers inside security firms that protect power grids and water systems. For maintainers, it means AI-written bug reports with a working exploit attached, at no cost.
How OSS Scanner works
OSS Scanner is free and opt-in, according to Anthropic's announcement. Anthropic says it was inspired by Google's OSS-Fuzz, a long-running service that tests open-source code with random inputs.
Core maintainers sign up their project, and eligibility is decided case by case. Unite.AI reports the criteria resemble OSS-Fuzz's: how much a project matters to infrastructure and to user security. Anthropic also wants projects that have the capacity to keep up with the findings.
Each report includes:
- a proof of concept, a small program that shows the bug can really be exploited
- an explanation of the flaw, including when the faulty code was added where possible
- a suggested fix, when one is available
The scans use Anthropic's most capable models, including Claude Mythos, Unite.AI reports.
Reports arrive without human review
The reports are written by a model and sent straight to maintainers. "The reports are model-generated and sent without human review," Anthropic says. Some will be wrong, for example with the wrong severity. Anthropic expects more than 90% of them to be true positives, meaning real bugs.
Projects that cannot triage reports on their own are handled differently. They still get human-checked disclosures under Anthropic's coordinated vulnerability disclosure policy, which gives maintainers time to fix a flaw before it is made public.
That trade-off matters. Google paused its open-source bug bounty on October 5 after a flood of AI-generated reports. Cyber Press notes that maintainers must still check each finding's exploitability, severity, duplication and patch.
The track record so far
Over the past six months, Anthropic flagged more than 29,000 candidate vulnerabilities in open-source code, Unite.AI and Cyber Press report. About 6,000 were reviewed by hand, and nearly 5,000 unverified reports went to maintainers who asked to see everything.
Expert penetration testers then checked 97 critical and high-severity findings across 48 projects:
| Result | Findings |
|---|---|
| Met the bar for disclosure | 85 (88%) |
| Real, but duplicates of known issues | 11 |
| False positives | 1 |
One maintainer gave a similar picture. "Of the 74 reports we received, all but two were valid, and five became CVEs," said Todd Ouska of wolfSSL, as quoted by Unite.AI. A CVE is a public ID for a confirmed security flaw.
Defending power grids and water systems
The second program is the Critical Infrastructure Defense Program. It gives Claude models, on-site engineers and Anthropic's threat research to trusted firms that protect operational technology, the control systems behind power grids, water systems, transport networks and government services. It starts with a small group of providers.
The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. "Critical infrastructure facing machine-speed threats requires machine-speed defense," said Daniel Bernard, chief business officer at CrowdStrike.
The mission grows out of Project Glasswing, Anthropic's earlier security program. Unite.AI reports Glasswing commitments of up to $100 million in model usage credits and $4 million in donations. Of that, $2.5 million went to Alpha-Omega and OpenSSF through the Linux Foundation and $1.5 million to the Apache Software Foundation. On October 6, Anthropic folded Glasswing into an expanded Cyber Verification Program with three access tiers: Defense, Red Team and Specialized, according to Cyber Press.
What this means for developers
- Maintainers: decide if you can handle the volume. Free scans are useful only if someone reads the reports. Sign up when you have time to triage, not before.
- Verify before you patch. Reports skip human review. Reproduce each proof of concept yourself and check the severity before you ship a fix or file a CVE.
- Watch for duplicates. Eleven of 97 checked findings were already known. Search your issue tracker before treating a report as new.
- Users of open-source libraries: expect more security releases. If scans reach widely used projects, patch releases may come faster. Keep your dependency updates moving.
- Infrastructure teams: ask your security vendor. If you buy from one of the 11 partners, ask how they plan to use Claude in your environment.
The real test is whether maintainers keep the service on after the first wave of reports.
This article was first published on Tech AI Wire.
Also available in
Deutsch Β· ζ₯ζ¬θͺ Β· FranΓ§ais Β· EspaΓ±ol Β· PortuguΓͺs
Related on Tech AI Wire
Sources
- Introducing the Anthropic Cyber Mission - Anthropic
- Anthropic Launches Cyber Mission for Critical Infrastructure, Open Source - Unite.AI
- Anthropic on a mission for better security of critical infrastructure and open source - ITdaily
- Anthropic Launches Cyber Mission to Secure Critical Infrastructure With Claude AI - Cyber Press
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.