Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 4 min read

Anthropic Cyber Mission: free scans for open-source code

Anthropic launched the Anthropic Cyber Mission on October 8, 2026, a long-term effort to help defenders secure critical infrastructure and open-source software. It starts with two programs. OSS Scanner gives open-source

Anthropic launched the Anthropic Cyber Mission on October 8, 2026, a long-term effort to help defenders secure critical infrastructure and open-source software. It starts with two programs. OSS Scanner gives open-source projects free, regular vulnerability scans from Anthropic's strongest models. A second program puts Claude models and Anthropic engineers inside security firms that protect power grids and water systems. For maintainers, it means AI-written bug reports with a working exploit attached, at no cost.

How OSS Scanner works

OSS Scanner is free and opt-in, according to Anthropic's announcement. Anthropic says it was inspired by Google's OSS-Fuzz, a long-running service that tests open-source code with random inputs.

Core maintainers sign up their project, and eligibility is decided case by case. Unite.AI reports the criteria resemble OSS-Fuzz's: how much a project matters to infrastructure and to user security. Anthropic also wants projects that have the capacity to keep up with the findings.

Each report includes:

  • a proof of concept, a small program that shows the bug can really be exploited
  • an explanation of the flaw, including when the faulty code was added where possible
  • a suggested fix, when one is available

The scans use Anthropic's most capable models, including Claude Mythos, Unite.AI reports.

Reports arrive without human review

The reports are written by a model and sent straight to maintainers. "The reports are model-generated and sent without human review," Anthropic says. Some will be wrong, for example with the wrong severity. Anthropic expects more than 90% of them to be true positives, meaning real bugs.

Projects that cannot triage reports on their own are handled differently. They still get human-checked disclosures under Anthropic's coordinated vulnerability disclosure policy, which gives maintainers time to fix a flaw before it is made public.

That trade-off matters. Google paused its open-source bug bounty on October 5 after a flood of AI-generated reports. Cyber Press notes that maintainers must still check each finding's exploitability, severity, duplication and patch.

The track record so far

Over the past six months, Anthropic flagged more than 29,000 candidate vulnerabilities in open-source code, Unite.AI and Cyber Press report. About 6,000 were reviewed by hand, and nearly 5,000 unverified reports went to maintainers who asked to see everything.

Expert penetration testers then checked 97 critical and high-severity findings across 48 projects:

Result Findings
Met the bar for disclosure 85 (88%)
Real, but duplicates of known issues 11
False positives 1

One maintainer gave a similar picture. "Of the 74 reports we received, all but two were valid, and five became CVEs," said Todd Ouska of wolfSSL, as quoted by Unite.AI. A CVE is a public ID for a confirmed security flaw.

Defending power grids and water systems

The second program is the Critical Infrastructure Defense Program. It gives Claude models, on-site engineers and Anthropic's threat research to trusted firms that protect operational technology, the control systems behind power grids, water systems, transport networks and government services. It starts with a small group of providers.

The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. "Critical infrastructure facing machine-speed threats requires machine-speed defense," said Daniel Bernard, chief business officer at CrowdStrike.

The mission grows out of Project Glasswing, Anthropic's earlier security program. Unite.AI reports Glasswing commitments of up to $100 million in model usage credits and $4 million in donations. Of that, $2.5 million went to Alpha-Omega and OpenSSF through the Linux Foundation and $1.5 million to the Apache Software Foundation. On October 6, Anthropic folded Glasswing into an expanded Cyber Verification Program with three access tiers: Defense, Red Team and Specialized, according to Cyber Press.

What this means for developers

  • Maintainers: decide if you can handle the volume. Free scans are useful only if someone reads the reports. Sign up when you have time to triage, not before.
  • Verify before you patch. Reports skip human review. Reproduce each proof of concept yourself and check the severity before you ship a fix or file a CVE.
  • Watch for duplicates. Eleven of 97 checked findings were already known. Search your issue tracker before treating a report as new.
  • Users of open-source libraries: expect more security releases. If scans reach widely used projects, patch releases may come faster. Keep your dependency updates moving.
  • Infrastructure teams: ask your security vendor. If you buy from one of the 11 partners, ask how they plan to use Claude in your environment.

The real test is whether maintainers keep the service on after the first wave of reports.

This article was first published on Tech AI Wire.

Also available in

Deutsch Β· ζ—₯本θͺž Β· FranΓ§ais Β· EspaΓ±ol Β· PortuguΓͺs

Related on Tech AI Wire

Sources

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.