Anthropic launches cyber mission with free vulnerability scanning for open-source projects

Anthropic launches cyber mission with free vulnerability scanning for open-source projects

N
News Editor
2026-10-09 06:20:07
Anthropic said on Oct. 8 that it has launched Anthropic Cyber Mission, a long-term effort focused on protecting critical infrastructure and open-source software. The first rollout includes two programs: the Critical Infrastructure Defense Program, aimed at strengthening protection for operational technology systems used in sectors such as power grids, water utilities and transportation, and OSS Scanner, a free service that regularly scans open-source projects for vulnerabilities. According to Anthropic’s Frontier Red Team, OSS Scanner is opt-in and modeled in part on Google’s OSS-Fuzz approach. Participating projects receive reports generated by Anthropic’s strongest models, including Claude Mythos. Those reports include proof-of-concept reproductions, vulnerability descriptions and, where possible, suggested fixes. Anthropic said the reports are produced entirely by models without human review or severity triage, which speeds delivery but can lead to mistakes. The company said it found more than 29,000 suspected vulnerabilities over the past six months, while human reviewers completed checks on only about 6,000 of them. Anthropic framed that gap as a staffing bottleneck. It also named 11 founding partners for its critical infrastructure program, including CrowdStrike, Palo Alto Networks and Deloitte.

Anthropic said on Oct. 8 that it has launched Anthropic Cyber Mission, a long-term initiative focused on protecting critical infrastructure and open-source software. The first phase has two parts: the Critical Infrastructure Defense Program for operational technology systems used in power, water and transportation, and OSS Scanner, a free service that regularly scans open-source projects for vulnerabilities.

OSS Scanner sends model-generated reports without human review

According to a post from Anthropic’s Frontier Red Team, OSS Scanner is opt-in and draws on Google’s OSS-Fuzz, which scans open-source software through fuzz testing. Projects that join receive regular scanning reports generated by Anthropic’s strongest models, including Claude Mythos.

Each report includes a proof of concept that reproduces the vulnerability, a description of the issue and, when possible, a suggested fix. Anthropic said the reports are produced entirely by the model, with no human review or triage. That makes the process faster, though the company said some reports may still be wrong, including cases where severity is rated too high.

Anthropic estimated the true positive rate will be above 90%. In early testing, the company asked penetration testers who review vulnerability disclosures to examine 97 high and critical vulnerabilities across 48 projects. Of those, 85, or 88%, met the disclosure standard. Of the remaining 12, 11 were real vulnerabilities that duplicated known issues, and one was a false positive.

wolfSSL, which took part in testing, said only two of the 74 reports it received were invalid, and five later became official CVE entries. Anton Arapov of OpenSSL said AI vulnerability reports from about 18 months ago were "terrible," but the latest reports, including the raw model output, were as good as submissions from humans and sometimes better.

Anthropic says staffing remains the bottleneck

Anthropic said it launched the service after using its latest models to scan important software projects around the world over the past six months, identifying more than 29,000 suspected vulnerabilities. Human reviewers, however, had completed reviews on only about 6,000 of them.

The company said some maintainers, after receiving the first batch of reports, asked to receive all unverified reports and suggested fixes at once. Anthropic said it has so far sent nearly 5,000 reports directly in response to those requests.

OSS Scanner is aimed at projects that can handle a large volume of reports. Eligibility is based on OSS-Fuzz-style criteria and reviewed case by case using a standard of whether the project has critical impact on infrastructure and user safety. Core maintainers can apply through GitHub. Projects without enough staffing will continue to use a coordinated disclosure process after human verification.

Critical infrastructure program starts with 11 partners

The Critical Infrastructure Defense Program will provide access to frontier Claude models, embedded engineers and threat research for vendors that deliver cybersecurity services to infrastructure operators.

The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

Anthropic also expanded its cybersecurity evaluation program earlier this week and folded Project Glasswing into it, allowing more defenders to use its strongest models.

Anthropic says AI may favor defenders in two years, but not yet

Anthropic said it expects AI to favor defenders in two years, but not necessarily in the near term. The company said the cost of exploiting vulnerabilities has already fallen, while validation, disclosure and patching remain slow and still depend heavily on people.

Within Project Glasswing, the time from finding a vulnerability to fixing it often runs for months. For operational technology equipment, patches also have to wait until they can be applied safely to machines in service. In a small number of cases, that process can take decades.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.