Anthropic introduces Cyber Mission to help protect critical infrastructure and open source with Claude
IA en un minuto newsroom · Editor: Jon Elgezabal

In 30 seconds
Anthropic is kicking off Cyber Mission, a long-haul plan to strengthen cyber defense with Claude. Its first piece brings together 11 companies, among them CrowdStrike and Rockwell Automation, to shield the power grid, water and transportation alongside Anthropic engineers. OSS Scanner, in turn, will give open-source projects that sign up periodic reviews at no cost.
Anthropic has introduced the Anthropic Cyber Mission, a long-term commitment to help secure the systems everyone depends on.
It aims to support defenders with tools, research, and resources, and it starts with two areas: critical infrastructure and open-source software. For the first, it is introducing the Critical Infrastructure Defense Program, a program that brings frontier Claude models, on-site engineers, and threat research to the providers that operators rely on to protect the operational technology behind power grids, water systems, and transportation. Its 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. According to the company, several of them are already working with Claude to fix vulnerabilities. For now, the first step is to work with a small cohort of providers to learn which strategies work best, and companies that build security products or services for critical infrastructure can register their interest as the program expands.
Anthropic explains that this operational technology (controllers, control software, and industrial networks built to last for decades) often cannot be taken offline to patch, so known vulnerabilities can stay unresolved for years. In June it had already launched a cyber defense program for US state, local, tribal, and territorial governments, and since then it has offered its models and technical support to more than half of all US states.
The company is also launching OSS Scanner, which offers open-source projects regular security scans from its strongest models, for free. Almost all software relies on open-source code, much of it maintained by small teams of volunteers. The service is opt-in, inspired by Google's OSS-Fuzz, and meant for projects with the capacity to keep up with what it finds. Each report includes a proof of concept of how the bug could be exploited, an explanation, and a suggested fix where one is available. The reports are generated by the model and sent without human review, so they arrive faster, but some will contain errors, such as a wrong severity rating. Anthropic expects a true-positive rate above 90%. Projects that cannot keep up will still receive human-verified disclosures, and the service is kept free by the Defender Advantage Fund, which the company launched in August.
According to the company, it is easier than ever to find vulnerabilities, but verifying, prioritizing, and fixing them remains challenging. It draws that lesson from Project Glasswing, in which its partners uncovered many vulnerabilities without yet achieving a sufficient reduction in cyber risk, and which it merged earlier this week into its Cyber Verification Program, expanded to give many more defenders access to its most capable models. Anthropic forecasts that in two years AI will favor defense, although it warns that in the near term that may not be true.
Why it matters · analysis and opinion
The hard part is no longer finding flaws but getting someone to fix them in time, and that is the bottleneck Anthropic itself acknowledges. By relying on consultancies and manufacturers that already work inside plants and industrial networks, the program reaches operators through a channel they already trust, although for now with a small group and the expansion planned for the coming months. For anyone maintaining an open-source project, OSS Scanner only helps if there are hands to review what arrives, because the reports are not checked by people and may contain errors. A company that depends on open libraries can start by knowing which ones it uses and whether their maintainers have signed up, because when a patch comes out, applying it will be up to the company.
Official source: Anthropic · Written with the help of AI: how we make the news


