Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

AI Can Find the Bugs. Who Fixes Them? Anthropic’s Cyber Mission Brings Free AI Scans to Open Source and Engineers to the Power Grid (AI Trends, 9 October 2026)

  1. Home   »  
  2. AI Can Find the Bugs. Who Fixes Them? Anthropic’s Cyber Mission Brings Free AI Scans to Open Source and Engineers to the Power Grid (AI Trends, 9 October 2026)

AI Can Find the Bugs. Who Fixes Them? Anthropic’s Cyber Mission Brings Free AI Scans to Open Source and Engineers to the Power Grid (AI Trends, 9 October 2026)

October 9, 2026October 9, 2026 admincybersecurityTagged AI security, AI trends, Anthropic, Anthropic Cyber Mission, bug bounty, Claude Mythos, critical infrastructure security, open source security, OSS Scanner, OT security, software supply chain, vulnerability management

What’s trending in AI on 9 October 2026: Anthropic has launched the Anthropic Cyber Mission, a long-term programme that points its most capable Claude models at two of the softest targets in modern security: the open-source code almost every business runs on, and the operational technology behind power grids, water systems and transport networks. The first piece, OSS Scanner, is a free, opt-in service that runs AI security audits on enrolled open-source projects and sends maintainers a proof of concept, an explanation and often a candidate fix. The second, the Critical Infrastructure Defense Program, sends frontier models, Anthropic engineers and threat research to 11 founding security partners, from CrowdStrike and Palo Alto Networks to Dragos, Rockwell Automation and Hitachi. The announcement is notable less for what the AI can find than for what Anthropic admits: finding bugs is no longer the hard part. Checking, ranking and fixing them is. Below: what launched, what the numbers show, why the find-fix gap matters, and role cards for maintainers, operators and everyone else.

Key takeaways

  • Free AI audits for open source. OSS Scanner periodically scans enrolled projects with Anthropic’s strongest models, including Claude Mythos, and Anthropic pays the full cost.
  • No human in the loop, by design. Reports go to maintainers without human review. Anthropic expects more than 90% to be true positives but warns some will be wrong.
  • The pilot looks strong. Of 97 critical and high-severity findings checked by expert testers across 48 projects, 85 met Anthropic’s disclosure bar and only one was a false positive.
  • Critical infrastructure gets people, not just models. Eleven founding partners will get frontier models, on-site engineers and threat research to protect grids, water and transport. Pricing was not disclosed.
  • The bottleneck has moved. Anthropic says months often pass between finding and fixing a flaw, and some operational technology fixes can take decades. Your patching process, not your scanner, is now the constraint.
AI can find the bugs. Who fixes them?Title card. Headline: AI can find the bugs. Who fixes them? Subhead: Anthropic’s Cyber Mission brings free AI scans to open source and on-site engineers to critical infrastructure. Three tags: OSS Scanner is free and opt-in for critical open-source projects; 11 founding partners for the Critical Infrastructure Defense Program; 85 of 97 expert-reviewed findings met the disclosure bar, 1 false positive. Illustration of a shield split into two halves, one showing code brackets and one showing a power pylon. { } OPEN SOURCE THE GRID AI TRENDS · 9 OCTOBER 2026 AI can find the bugs. Who fixes them? Anthropic’s Cyber Mission: free AI scans for open source, and on-site engineers for power, water and transport. OSS Scanner: free, opt-in, no human review 11 founding partners for critical infrastructure Pilot: 85 of 97 findings met the bar, 1 false positive Sources: Anthropic (8 Oct 2026); Anthropic Frontier Red Team; Unite.AI; Resultsensedelana.co
Anthropic’s new Cyber Mission splits into two tracks: open-source code and the physical infrastructure that runs on it.

1. What Anthropic launched on 8 October

Anthropic describes the Cyber Mission as an effort that will take years and change as it learns, starting with two areas where it thinks AI can help defenders most: critical infrastructure and open-source software. Both pieces build on Project Glasswing, the April programme that gave selected organisations access to Claude Mythos Preview for defensive security work, and which Anthropic folded into its expanded Cyber Verification Program two days earlier.

Critical Infrastructure Defense ProgramOSS Scanner
Who it is forSecurity vendors, system integrators and equipment makers that protect critical infrastructureCore maintainers of open-source projects with critical impact on infrastructure and user security
What they getFrontier Claude models, Anthropic engineers on site, Anthropic threat researchPeriodic AI scans; reports with a reproducer, explanation, bisection where possible and a candidate patch
Systems in scopeOperational technology for power, water, transport and government systemsEnrolled open-source repositories
CostNot disclosedFree; Anthropic covers the full cost
How to joinRegister interest; starts with a small cohort and expands over the coming monthsPull request to the anthropics/oss-scanner GitHub repo; accepted case by case
Human reviewAnthropic engineers work alongside partnersNone before delivery; reports are fully model-generated
Compiled from Anthropic’s Cyber Mission announcement, its Frontier Red Team launch post and the OSS Scanner FAQ, 8–9 October 2026.

The 11 founding partners of the infrastructure programme are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. The mix spans consultancies, industrial security specialists such as Dragos and Nozomi, and manufacturers such as Hitachi and Rockwell that build the equipment and ship its patches. The programme reaches operators only through those providers; a water utility does not sign up directly. Anthropic says work is already under way with several partners. Neither Anthropic nor the coverage we read says who pays for the compute or what partners pay, a gap Korean outlet DigitalToday also flagged.

2. How OSS Scanner works

OSS Scanner is modelled on Google’s long-running OSS-Fuzz, which throws automated fuzzing at enrolled open-source projects. Anthropic’s version swaps fuzzers for language models. A core maintainer enrols a project by opening a pull request that adds a small project file and a Dockerfile that installs every dependency, so the scanner can build and run the code offline. Anthropic verifies the maintainer and decides case by case, weighing remote-attack exposure and how many users and dependent projects there are.

After enrolment the scanner runs a first full pass, then rescans regularly for newly introduced bugs and ones it missed. Anthropic does not give a fixed schedule; frequency depends on load and how widely the project is used. Each report includes a self-contained reproducer, an explanation, a bisection showing when the bug was introduced where possible, and a candidate patch when one is available. Maintainers can pause reports at any time by adding a single line to their config, or leave entirely by deleting their project folder.

How OSS Scanner works, step by stepFive-step flow. Step 1, enroll: a core maintainer opens a pull request to the anthropics/oss-scanner repository with a project file and a Dockerfile. Step 2, first scan: a full pass by Anthropic’s strongest models including Claude Mythos. Step 3, rescans: periodic scans for newly introduced and previously missed bugs. Step 4, report: a reproducer, an explanation, a bisection where possible and a candidate patch, sent without human review. Step 5, the maintainer decides: fix it, reply with feedback, or pause reports with disabled: true. A bottom bar notes that unvalidated reports carry no 90-day disclosure clock; the clock starts only if Anthropic validates a finding through its standard disclosure process. How OSS Scanner works, step by step Free and opt-in for critical open-source projects; Anthropic covers the compute 1. EnrollPR to anthropics/oss-scanner + Dockerfile2. First scanFull pass with topmodels incl. Mythos3. RescansPeriodic: new codeand missed bugs4. ReportReproducer, why,bisection, patch5. You decideFix, reply, or pausewith disabled: true Reports are fully model-generated and sent without human review No 90-day disclosure clock on unvalidated reports; it starts only after human validation Source: Anthropic Frontier Red Team launch post and OSS Scanner FAQ (Oct 2026). Simplified illustration.delana.co
The scanner is built for speed: reports arrive without a human check, so the maintainer is the first reviewer.

Two design choices matter. First, there is no human review before a report is sent. Anthropic’s Frontier Red Team says plainly that reports may be incorrect or invalid. Second, unvalidated findings carry no 90-day disclosure clock. Anthropic only starts that clock if it later validates a finding through its standard coordinated vulnerability disclosure (CVD) process. That spares maintainers a deadline on an AI’s guess, but also means real bugs could sit unread with no outside pressure to fix them.

3. What the pilot numbers show, and what they don’t

Anthropic published unusually specific numbers. Over the past six months, its models flagged more than 29,000 candidate vulnerabilities across major projects. Around 6,000 were reviewed and triaged by hand, and nearly 5,000 unverified reports went straight to maintainers who had asked to receive everything. To test quality, expert penetration testers checked 97 critical and high-severity findings across 48 projects: 85 (88%) met the bar for Anthropic’s disclosure process, 11 were real but duplicated known issues or other findings, and just one was a false positive.

From 29,000 candidate bugs to one false positiveFunnel chart of Anthropic’s six-month scanning numbers. Top: more than 29,000 candidate vulnerabilities flagged by models. Next: about 6,000 manually triaged by people. Next: 97 critical and high-severity findings across 48 projects checked by expert penetration testers. Bottom split: 85 findings, or 88 percent, met the bar for coordinated disclosure; 11 were real but duplicates of known issues or other findings; 1 was a false positive. A side note says nearly 5,000 unverified reports went straight to maintainers who asked for everything. From 29,000 candidate bugs to one false positive Anthropic’s own numbers from six months of AI-driven open-source scanning 29,000+candidate vulnerabilities flagged by models~6,000triaged by hand97critical/high findings checked by pen testers, 48 projects 85 (88%)met the disclosure bar 11real, but duplicates 1false positive Side channel: nearly 5,000 unverified reports went directly to maintainers who asked to receive everything. Source: Anthropic Frontier Red Team, OSS Scanner launch post (8 Oct 2026). Bar widths illustrative, not to scale.delana.co
Anthropic’s funnel: thousands of AI candidates, a small expert-checked sample, and one false positive in that sample.

The maintainer feedback is encouraging too. Todd Ouska of wolfSSL, the widely embedded TLS library, told Anthropic that of the 74 reports his team received, “all but two were valid,” and five became CVEs.

Read the numbers carefully, though. The 97-finding sample is critical and high-severity issues chosen for expert review, not a random draw from all 29,000 candidates, so it says more about the scanner’s best output than its average. Anthropic itself does not claim the 99% “real” rate the sample implies; it says it expects more than 90% true positives across the service. And maintainers have told Anthropic that severity ratings are sometimes inflated or that the scanner misreads a project’s threat model. A bug that is technically real can still be irrelevant to how the software is actually used.

Context matters here. Earlier this month Google stopped accepting product bug reports in its open-source reward programme after a flood of hallucinated AI submissions, which we covered in AI broke the bug bounty. OSS Scanner is Anthropic’s bet that the answer is not fewer AI reports but better ones, sent only to projects that ask for them.

4. The real story: the find-fix gap

The most important line in Anthropic’s announcement is an admission. Anthropic forecasts that within two years AI will tilt the balance toward defenders, but says that may not hold in the near term, because months often pass between a vulnerability being found and fixed. For operational technology the gap is worse: a fix may have to wait for a safe moment to take a substation or a treatment plant offline, and in rare cases, Anthropic notes, deployment can take decades.

Meanwhile, attackers are getting faster. Microsoft’s 2026 Digital Defense Report found flaws are now often weaponised in well under 24 hours, as we explained in the 24-hour window. And the same capabilities are spreading beyond trusted labs: Anthropic found China’s open-weight GLM-5.3 nearly matches Mythos at building exploits, and NIST called it the most cyber-capable open model yet, covered in elite AI hacking just went open-weight. When both sides can find bugs cheaply, whoever fixes faster wins.

The find-fix gapHorizontal bar chart showing relative effort and time for five stages of handling a vulnerability. Find: done by AI models, now automated and cheap, shortest bar. Validate: mostly people, checking whether a finding is real and new. Prioritise: people decide how bad it is and for whom. Fix in IT systems: maintainers and vendors, where months can pass. Fix in operational technology: operators and manufacturers, which waits for safe downtime and in rare cases takes decades, longest bar. Bars are illustrative, not measured durations. The find-fix gap: AI shortened only the first bar Where the time goes between discovering a flaw and closing it FindAI modelsNow automated and cheapValidateMostly peopleIs it real? Is it new?PrioritisePeopleHow bad, for whom?Fix (IT)Maintainers, vendorsMonths can passFix (OT)Operators, makersWaits for safe downtime; in rare cases decades Source: Anthropic, Cyber Mission announcement (8 Oct 2026). Bar lengths are illustrative, not measured durations.delana.co
AI has compressed discovery. Validation, prioritisation and especially patching still run at human and operational speed.

That is why the infrastructure half of the mission is about engineers on site, not just model access. Industrial systems often run continuously for decades and cannot simply be rebooted to patch, as we described in industrial and critical infrastructure under siege. The useful AI work there is choosing compensating controls, segmentation and configuration changes that cut risk until a patch can go in. CrowdStrike, one of the partners, summed up the pitch to Unite.AI: machine-speed threats need “machine-speed defense.”

5. Where this fits in Anthropic’s cyber stack

The Cyber Mission is the latest of several moves this year. In June Anthropic launched a defence programme for state, local, tribal and territorial governments, which it says has since offered models and support to more than half of US states. In August it created the Defender Advantage Fund, which pays for pilots and keeps OSS Scanner free. And on 6 October it expanded its Cyber Verification Program into three access tiers, absorbing Project Glasswing. We wrote about the first wave of this gated approach in the best cyber models going behind a velvet rope.

TierWho can applyWhat it allows
Defense AccessCompany, nonprofit, university and government security teams; critical-infrastructure operators of any size; open-source maintainers; individual researchers with a disclosure recordSecurity operations, incident response, malware analysis, vulnerability analysis and validation, with fewer blocks
Red Team AccessOrganisations only: in-house and government red teams, penetration-testing firmsAuthorised penetration testing of systems the organisation may test; physically harmful or mass-disruption actions still blocked
Specialized AccessA limited set of verified organisations, reviewed with the US governmentTesting of safety-critical systems such as power grids, telecoms and interbank transfers; former Glasswing members move here
Anthropic’s expanded Cyber Verification Program, as reported by Unite.AI, 6 October 2026. Defense Access requires phishing-resistant MFA and no API keys by 15 December 2026.
Anthropic’s 2026 cyber defence movesTimeline of Anthropic’s 2026 cybersecurity initiatives. 7 April: Project Glasswing, Claude Mythos access with up to 100 million dollars in usage credits. June: a cyber defence program for state, local, tribal and territorial governments. August: the Defender Advantage Fund, which pays for pilots and keeps OSS Scanner free. 6 October: the Cyber Verification Program expands to three tiers and absorbs Glasswing. 8 October: the Cyber Mission launches the Critical Infrastructure Defense Program and OSS Scanner. Six months, five moves: Anthropic’s 2026 cyber timeline From restricted model access to free scanning and on-site help 7 AprProject GlasswingMythos access, up to $100M creditsJunGovernment programState, local, tribal, territorialAugDefender Advantage FundPays for pilots, keeps scanner free6 OctCyber Verification Program3 tiers; Glasswing folded in8 OctCyber MissionCIDP + OSS Scanner Direction of travel: from “who may use the model” to “who will fix what it finds” Sources: Anthropic; Unite.AI (6 and 8 Oct 2026). Delana analysis.delana.co
The arc of 2026: from restricting who may use powerful cyber models to paying for the people and processes that act on their findings.

The scale explains the shift. Anthropic says Glasswing partners reported at least 129,000 verified vulnerabilities between April and July, more than 33,000 of them critical or high, and calls that a likely undercount. Finding bugs at that rate without a matching fix pipeline just turns unknown risk into known, unpatched risk.

6. What it means if you are not a maintainer or a utility

Most businesses will never enrol in either programme, but both will reach them. Every web app, firewall and laptop depends on open-source libraries, so better-scanned upstream code is good news. The flip side is volume: if AI scanning works, expect more security advisories and more patch releases for the components you already run, arriving faster. A business that patches quarterly will fall further behind, and the regulatory clock is tightening too, as we set out in stricter patch deadlines.

There is also a vendor question. If your security provider is one of the 11 partners, ask what the programme changes for you: which models touch your operational data, where that data goes, and whether AI-suggested fixes are tested before they reach production. The White House AI Accord left those assurances voluntary, as we noted in our accord explainer, so the contract is where you get them in writing.

7. Role cards: who does what now

One card per group this launch affects. Most businesses are Card C.

Card A: Open-source maintainers

  1. Check capacity first. Anthropic aims the scanner at projects that can already keep up with verified high and critical reports. If one person handles security in spare time, line up a second reviewer before you enrol.
  2. Write a threat model. The config accepts an optional threat-model field. Use it, since maintainers say the scanner sometimes misreads how a project is meant to be used.
  3. Treat each report as a lead, not a verdict. Run the reproducer, confirm the bug, and re-rate severity yourself before filing a CVE.
  4. Review the AI patch like any outside contribution. Read it, test it and check it does not break behaviour or add new risk.
  5. Use the pause switch. If reports outrun your capacity, pause with disabled: true rather than let findings pile up unread.

Card B: Critical infrastructure operators

  1. Ask your providers. If you work with any of the 11 partners, ask whether you are in the first cohort and what changes in their service.
  2. Map patch windows now. List which systems can only be patched during planned outages, and when the next window is.
  3. Plan compensating controls. For flaws that cannot be patched soon, agree segmentation, monitoring and configuration changes in advance.
  4. Set data rules for AI. Decide what network diagrams, configs and logs may be shared with an AI-assisted provider, and under what retention terms.
  5. Consider Defense Access. Operators of any size can apply to Anthropic’s verification programme; note the phishing-resistant MFA requirement by 15 December.

Card C: Every business that runs open-source software

  1. Know what you run. Keep a software bill of materials, or at least a dependency list, for your main applications.
  2. Shorten the patch cycle. Move critical and high advisories for internet-facing components to days, not the next quarterly cycle.
  3. Watch upstream. Subscribe to security advisories for your most important libraries, since AI scanning will raise their volume.
  4. Be wary of AI-generated reports sent to you. If someone emails a dramatic AI-found flaw in your site, verify it before panicking or paying anyone.
  5. Ask vendors one question. “How fast do you ship fixes for critical upstream open-source flaws, and how will we hear about them?”

8. What to watch next

  • Real-world false positives. The 1-in-97 pilot figure covers a hand-picked sample. Watch for maintainer reports once hundreds of projects are enrolled.
  • Disclosure policy. Anthropic says it may add a disclosure period for some high-severity reports. That would change the pressure on maintainers who receive them.
  • Who pays for the infrastructure programme. Pricing and compute costs were not disclosed; watch partner announcements for terms.
  • The Cyber Verification Program webinar on 14 October. Expect more detail on eligibility and the December security requirements.

Frequently asked questions

What is the Anthropic Cyber Mission?

Announced on 8 October 2026, the Anthropic Cyber Mission is a long-term programme to help defenders with AI tools, research and funding. It starts with two parts: the Critical Infrastructure Defense Program for operational technology such as power, water and transport, and OSS Scanner, a free AI vulnerability scanning service for open-source projects.

What is Anthropic’s OSS Scanner?

OSS Scanner is a free, opt-in service that periodically scans enrolled open-source projects with Anthropic’s most capable models, including Claude Mythos. Each report includes a reproducer, an explanation, a bisection where possible and a candidate patch. Reports are sent without human review, and Anthropic expects more than 90% to be true positives.

How does an open-source project join OSS Scanner?

A core maintainer opens a pull request to the anthropics/oss-scanner GitHub repository adding a project file and a Dockerfile that installs all dependencies. Anthropic verifies the maintainer and accepts projects case by case, using criteria similar to Google’s OSS-Fuzz, such as exposure to remote attack and the number of users and dependent projects.

Which companies are in the Critical Infrastructure Defense Program?

The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. They receive frontier Claude models, on-site Anthropic engineers and threat research. Other security vendors, integrators and equipment makers serving critical infrastructure can register interest.

How accurate is Anthropic’s AI vulnerability scanner?

In Anthropic’s pilot, expert testers checked 97 critical and high-severity findings across 48 projects: 85 met its disclosure bar, 11 were real but duplicates and 1 was a false positive. That sample was selected, not random, and maintainers say some severity ratings were inflated. Anthropic’s own expectation is a true-positive rate above 90%.

What should a business do about AI-found vulnerabilities?

Expect more security advisories for the open-source components you run. Keep a dependency list, shorten patch cycles for critical and high flaws in internet-facing systems, subscribe to upstream advisories and ask vendors how quickly they ship fixes. Verify any unsolicited AI-generated vulnerability report before acting on it. This is general guidance, not legal advice.


Sources

  • Anthropic: Introducing the Anthropic Cyber Mission (8 Oct 2026)
  • Anthropic Frontier Red Team: Launching an opt-in vulnerability-finding service for open source (8 Oct 2026, updated 9 Oct)
  • Anthropic: OSS Scanner FAQ
  • Unite.AI: Anthropic Launches Cyber Mission for Critical Infrastructure, Open Source (Oct 2026)
  • Unite.AI: Anthropic Expands Cyber Verification Program to Three Access Tiers (6 Oct 2026)
  • Resultsense: Anthropic’s Cyber Mission targets grids and open source (9 Oct 2026)
  • DigitalToday: Anthropic launches OT security support program, releases free open-source vulnerability scanner (9 Oct 2026)

Post navigation

Previous: Your Next Coworker Has a Gmail Address: Google’s Gemini Agent Gets Its Own Workspace Account as the UK Privacy Regulator Turns to AI Agents (AI Trends, 8 October 2026)

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC