What’s trending in AI on 9 October 2026: Anthropic has launched the Anthropic Cyber Mission, a long-term programme that points its most capable Claude models at two of the softest targets in modern security: the open-source code almost every business runs on, and the operational technology behind power grids, water systems and transport networks. The first piece, OSS Scanner, is a free, opt-in service that runs AI security audits on enrolled open-source projects and sends maintainers a proof of concept, an explanation and often a candidate fix. The second, the Critical Infrastructure Defense Program, sends frontier models, Anthropic engineers and threat research to 11 founding security partners, from CrowdStrike and Palo Alto Networks to Dragos, Rockwell Automation and Hitachi. The announcement is notable less for what the AI can find than for what Anthropic admits: finding bugs is no longer the hard part. Checking, ranking and fixing them is. Below: what launched, what the numbers show, why the find-fix gap matters, and role cards for maintainers, operators and everyone else.
Key takeaways
- Free AI audits for open source. OSS Scanner periodically scans enrolled projects with Anthropic’s strongest models, including Claude Mythos, and Anthropic pays the full cost.
- No human in the loop, by design. Reports go to maintainers without human review. Anthropic expects more than 90% to be true positives but warns some will be wrong.
- The pilot looks strong. Of 97 critical and high-severity findings checked by expert testers across 48 projects, 85 met Anthropic’s disclosure bar and only one was a false positive.
- Critical infrastructure gets people, not just models. Eleven founding partners will get frontier models, on-site engineers and threat research to protect grids, water and transport. Pricing was not disclosed.
- The bottleneck has moved. Anthropic says months often pass between finding and fixing a flaw, and some operational technology fixes can take decades. Your patching process, not your scanner, is now the constraint.
1. What Anthropic launched on 8 October
Anthropic describes the Cyber Mission as an effort that will take years and change as it learns, starting with two areas where it thinks AI can help defenders most: critical infrastructure and open-source software. Both pieces build on Project Glasswing, the April programme that gave selected organisations access to Claude Mythos Preview for defensive security work, and which Anthropic folded into its expanded Cyber Verification Program two days earlier.
| Critical Infrastructure Defense Program | OSS Scanner | |
|---|---|---|
| Who it is for | Security vendors, system integrators and equipment makers that protect critical infrastructure | Core maintainers of open-source projects with critical impact on infrastructure and user security |
| What they get | Frontier Claude models, Anthropic engineers on site, Anthropic threat research | Periodic AI scans; reports with a reproducer, explanation, bisection where possible and a candidate patch |
| Systems in scope | Operational technology for power, water, transport and government systems | Enrolled open-source repositories |
| Cost | Not disclosed | Free; Anthropic covers the full cost |
| How to join | Register interest; starts with a small cohort and expands over the coming months | Pull request to the anthropics/oss-scanner GitHub repo; accepted case by case |
| Human review | Anthropic engineers work alongside partners | None before delivery; reports are fully model-generated |
The 11 founding partners of the infrastructure programme are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. The mix spans consultancies, industrial security specialists such as Dragos and Nozomi, and manufacturers such as Hitachi and Rockwell that build the equipment and ship its patches. The programme reaches operators only through those providers; a water utility does not sign up directly. Anthropic says work is already under way with several partners. Neither Anthropic nor the coverage we read says who pays for the compute or what partners pay, a gap Korean outlet DigitalToday also flagged.
2. How OSS Scanner works
OSS Scanner is modelled on Google’s long-running OSS-Fuzz, which throws automated fuzzing at enrolled open-source projects. Anthropic’s version swaps fuzzers for language models. A core maintainer enrols a project by opening a pull request that adds a small project file and a Dockerfile that installs every dependency, so the scanner can build and run the code offline. Anthropic verifies the maintainer and decides case by case, weighing remote-attack exposure and how many users and dependent projects there are.
After enrolment the scanner runs a first full pass, then rescans regularly for newly introduced bugs and ones it missed. Anthropic does not give a fixed schedule; frequency depends on load and how widely the project is used. Each report includes a self-contained reproducer, an explanation, a bisection showing when the bug was introduced where possible, and a candidate patch when one is available. Maintainers can pause reports at any time by adding a single line to their config, or leave entirely by deleting their project folder.
Two design choices matter. First, there is no human review before a report is sent. Anthropic’s Frontier Red Team says plainly that reports may be incorrect or invalid. Second, unvalidated findings carry no 90-day disclosure clock. Anthropic only starts that clock if it later validates a finding through its standard coordinated vulnerability disclosure (CVD) process. That spares maintainers a deadline on an AI’s guess, but also means real bugs could sit unread with no outside pressure to fix them.
3. What the pilot numbers show, and what they don’t
Anthropic published unusually specific numbers. Over the past six months, its models flagged more than 29,000 candidate vulnerabilities across major projects. Around 6,000 were reviewed and triaged by hand, and nearly 5,000 unverified reports went straight to maintainers who had asked to receive everything. To test quality, expert penetration testers checked 97 critical and high-severity findings across 48 projects: 85 (88%) met the bar for Anthropic’s disclosure process, 11 were real but duplicated known issues or other findings, and just one was a false positive.
The maintainer feedback is encouraging too. Todd Ouska of wolfSSL, the widely embedded TLS library, told Anthropic that of the 74 reports his team received, “all but two were valid,” and five became CVEs.
Read the numbers carefully, though. The 97-finding sample is critical and high-severity issues chosen for expert review, not a random draw from all 29,000 candidates, so it says more about the scanner’s best output than its average. Anthropic itself does not claim the 99% “real” rate the sample implies; it says it expects more than 90% true positives across the service. And maintainers have told Anthropic that severity ratings are sometimes inflated or that the scanner misreads a project’s threat model. A bug that is technically real can still be irrelevant to how the software is actually used.
Context matters here. Earlier this month Google stopped accepting product bug reports in its open-source reward programme after a flood of hallucinated AI submissions, which we covered in AI broke the bug bounty. OSS Scanner is Anthropic’s bet that the answer is not fewer AI reports but better ones, sent only to projects that ask for them.
4. The real story: the find-fix gap
The most important line in Anthropic’s announcement is an admission. Anthropic forecasts that within two years AI will tilt the balance toward defenders, but says that may not hold in the near term, because months often pass between a vulnerability being found and fixed. For operational technology the gap is worse: a fix may have to wait for a safe moment to take a substation or a treatment plant offline, and in rare cases, Anthropic notes, deployment can take decades.
Meanwhile, attackers are getting faster. Microsoft’s 2026 Digital Defense Report found flaws are now often weaponised in well under 24 hours, as we explained in the 24-hour window. And the same capabilities are spreading beyond trusted labs: Anthropic found China’s open-weight GLM-5.3 nearly matches Mythos at building exploits, and NIST called it the most cyber-capable open model yet, covered in elite AI hacking just went open-weight. When both sides can find bugs cheaply, whoever fixes faster wins.
That is why the infrastructure half of the mission is about engineers on site, not just model access. Industrial systems often run continuously for decades and cannot simply be rebooted to patch, as we described in industrial and critical infrastructure under siege. The useful AI work there is choosing compensating controls, segmentation and configuration changes that cut risk until a patch can go in. CrowdStrike, one of the partners, summed up the pitch to Unite.AI: machine-speed threats need “machine-speed defense.”
5. Where this fits in Anthropic’s cyber stack
The Cyber Mission is the latest of several moves this year. In June Anthropic launched a defence programme for state, local, tribal and territorial governments, which it says has since offered models and support to more than half of US states. In August it created the Defender Advantage Fund, which pays for pilots and keeps OSS Scanner free. And on 6 October it expanded its Cyber Verification Program into three access tiers, absorbing Project Glasswing. We wrote about the first wave of this gated approach in the best cyber models going behind a velvet rope.
| Tier | Who can apply | What it allows |
|---|---|---|
| Defense Access | Company, nonprofit, university and government security teams; critical-infrastructure operators of any size; open-source maintainers; individual researchers with a disclosure record | Security operations, incident response, malware analysis, vulnerability analysis and validation, with fewer blocks |
| Red Team Access | Organisations only: in-house and government red teams, penetration-testing firms | Authorised penetration testing of systems the organisation may test; physically harmful or mass-disruption actions still blocked |
| Specialized Access | A limited set of verified organisations, reviewed with the US government | Testing of safety-critical systems such as power grids, telecoms and interbank transfers; former Glasswing members move here |
The scale explains the shift. Anthropic says Glasswing partners reported at least 129,000 verified vulnerabilities between April and July, more than 33,000 of them critical or high, and calls that a likely undercount. Finding bugs at that rate without a matching fix pipeline just turns unknown risk into known, unpatched risk.
6. What it means if you are not a maintainer or a utility
Most businesses will never enrol in either programme, but both will reach them. Every web app, firewall and laptop depends on open-source libraries, so better-scanned upstream code is good news. The flip side is volume: if AI scanning works, expect more security advisories and more patch releases for the components you already run, arriving faster. A business that patches quarterly will fall further behind, and the regulatory clock is tightening too, as we set out in stricter patch deadlines.
There is also a vendor question. If your security provider is one of the 11 partners, ask what the programme changes for you: which models touch your operational data, where that data goes, and whether AI-suggested fixes are tested before they reach production. The White House AI Accord left those assurances voluntary, as we noted in our accord explainer, so the contract is where you get them in writing.
7. Role cards: who does what now
One card per group this launch affects. Most businesses are Card C.
Card A: Open-source maintainers
- Check capacity first. Anthropic aims the scanner at projects that can already keep up with verified high and critical reports. If one person handles security in spare time, line up a second reviewer before you enrol.
- Write a threat model. The config accepts an optional threat-model field. Use it, since maintainers say the scanner sometimes misreads how a project is meant to be used.
- Treat each report as a lead, not a verdict. Run the reproducer, confirm the bug, and re-rate severity yourself before filing a CVE.
- Review the AI patch like any outside contribution. Read it, test it and check it does not break behaviour or add new risk.
- Use the pause switch. If reports outrun your capacity, pause with disabled: true rather than let findings pile up unread.
Card B: Critical infrastructure operators
- Ask your providers. If you work with any of the 11 partners, ask whether you are in the first cohort and what changes in their service.
- Map patch windows now. List which systems can only be patched during planned outages, and when the next window is.
- Plan compensating controls. For flaws that cannot be patched soon, agree segmentation, monitoring and configuration changes in advance.
- Set data rules for AI. Decide what network diagrams, configs and logs may be shared with an AI-assisted provider, and under what retention terms.
- Consider Defense Access. Operators of any size can apply to Anthropic’s verification programme; note the phishing-resistant MFA requirement by 15 December.
Card C: Every business that runs open-source software
- Know what you run. Keep a software bill of materials, or at least a dependency list, for your main applications.
- Shorten the patch cycle. Move critical and high advisories for internet-facing components to days, not the next quarterly cycle.
- Watch upstream. Subscribe to security advisories for your most important libraries, since AI scanning will raise their volume.
- Be wary of AI-generated reports sent to you. If someone emails a dramatic AI-found flaw in your site, verify it before panicking or paying anyone.
- Ask vendors one question. “How fast do you ship fixes for critical upstream open-source flaws, and how will we hear about them?”
8. What to watch next
- Real-world false positives. The 1-in-97 pilot figure covers a hand-picked sample. Watch for maintainer reports once hundreds of projects are enrolled.
- Disclosure policy. Anthropic says it may add a disclosure period for some high-severity reports. That would change the pressure on maintainers who receive them.
- Who pays for the infrastructure programme. Pricing and compute costs were not disclosed; watch partner announcements for terms.
- The Cyber Verification Program webinar on 14 October. Expect more detail on eligibility and the December security requirements.
Frequently asked questions
What is the Anthropic Cyber Mission?
Announced on 8 October 2026, the Anthropic Cyber Mission is a long-term programme to help defenders with AI tools, research and funding. It starts with two parts: the Critical Infrastructure Defense Program for operational technology such as power, water and transport, and OSS Scanner, a free AI vulnerability scanning service for open-source projects.
What is Anthropic’s OSS Scanner?
OSS Scanner is a free, opt-in service that periodically scans enrolled open-source projects with Anthropic’s most capable models, including Claude Mythos. Each report includes a reproducer, an explanation, a bisection where possible and a candidate patch. Reports are sent without human review, and Anthropic expects more than 90% to be true positives.
How does an open-source project join OSS Scanner?
A core maintainer opens a pull request to the anthropics/oss-scanner GitHub repository adding a project file and a Dockerfile that installs all dependencies. Anthropic verifies the maintainer and accepts projects case by case, using criteria similar to Google’s OSS-Fuzz, such as exposure to remote attack and the number of users and dependent projects.
Which companies are in the Critical Infrastructure Defense Program?
The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. They receive frontier Claude models, on-site Anthropic engineers and threat research. Other security vendors, integrators and equipment makers serving critical infrastructure can register interest.
How accurate is Anthropic’s AI vulnerability scanner?
In Anthropic’s pilot, expert testers checked 97 critical and high-severity findings across 48 projects: 85 met its disclosure bar, 11 were real but duplicates and 1 was a false positive. That sample was selected, not random, and maintainers say some severity ratings were inflated. Anthropic’s own expectation is a true-positive rate above 90%.
What should a business do about AI-found vulnerabilities?
Expect more security advisories for the open-source components you run. Keep a dependency list, shorten patch cycles for critical and high flaws in internet-facing systems, subscribe to upstream advisories and ask vendors how quickly they ship fixes. Verify any unsolicited AI-generated vulnerability report before acting on it. This is general guidance, not legal advice.
Sources
- Anthropic: Introducing the Anthropic Cyber Mission (8 Oct 2026)
- Anthropic Frontier Red Team: Launching an opt-in vulnerability-finding service for open source (8 Oct 2026, updated 9 Oct)
- Anthropic: OSS Scanner FAQ
- Unite.AI: Anthropic Launches Cyber Mission for Critical Infrastructure, Open Source (Oct 2026)
- Unite.AI: Anthropic Expands Cyber Verification Program to Three Access Tiers (6 Oct 2026)
- Resultsense: Anthropic’s Cyber Mission targets grids and open source (9 Oct 2026)
- DigitalToday: Anthropic launches OT security support program, releases free open-source vulnerability scanner (9 Oct 2026)
