█

AI/TLDR

Anthropic · 2026-10-08 · major

Anthropic Cyber Mission — free OSS Scanner and a grid-defense program

Anthropic's Cyber Mission launches OSS Scanner, a free opt-in service that scans critical open-source projects with its strongest models, plus a program that brings Claude to power, water and transport defenders.

Anthropic illustration for the Cyber Mission announcement

Anthropic gives open-source maintainers free AI vulnerability scans and sends Claude to grid and water defenders.

Quick facts

MakerAnthropic
AnnouncedOctober 8, 2026
OSS Scanner priceFree for open-source projects
How to enrollCore maintainers open a PR to anthropics/oss-scanner
Early true-positive rate85 of 97 findings (88%) met the CVD bar; 1 false positive
Infrastructure programCritical Infrastructure Defense Program (CIDP), 11 founding partners

What is it?

Anthropic's Cyber Mission is a long-term security effort with two new parts. OSS Scanner is a free, opt-in service that runs periodic vulnerability scans on critical open-source projects using Anthropic's strongest models, including Claude Mythos. The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers and threat research to companies that protect power grids, water systems and transport.

How does it work?

Maintainers enroll a project by adding a config file and a Dockerfile to the anthropics/oss-scanner repo. The scanner then sends reports straight to them before any human review, each with a reproducer, an explanation, a bisection to the commit that added the bug where possible, and a candidate patch. Anthropic says it found over 29,000 candidate vulnerabilities in six months and manually reviewed about 6,000.

Why does it matter?

Open-source maintainers get the kind of AI bug hunting Anthropic used in Project Glasswing for free, and much faster than human-reviewed disclosure. The trade-off is that reports arrive unchecked, so the service is meant for projects that can keep up with the volume.

Who is it for?

open-source maintainers and critical-infrastructure security teams

Frequently asked questions

How does an open-source project join Anthropic's OSS Scanner?
A core maintainer joins OSS Scanner by opening a pull request to the anthropics/oss-scanner GitHub repo that adds a project.yaml file with the repo, a primary contact and a Dockerfile. Anthropic checks that the person is a core maintainer. Eligibility is decided case by case and looks like OSS-Fuzz's rules, such as exposure to remote attacks and the number of users or dependent projects.
Are OSS Scanner reports checked by a human?
No. OSS Scanner reports are fully model-generated, without human review or triage, so some can be wrong. Each report includes a reproducer, an explanation of the bug and, when available, a candidate patch. Unvalidated findings have no 90-day disclosure deadline. Findings that Anthropic's team does verify still go through its normal coordinated vulnerability disclosure process.
How accurate was OSS Scanner in testing?
In Anthropic's early test, expert penetration testers reviewed 97 critical and high-severity OSS Scanner findings across 48 projects. 85 of them (88%) met the bar for Anthropic's disclosure process. Of the other 12, 11 were real bugs that duplicated known issues, and only one was a false positive. wolfSSL said all but two of its 74 reports were valid, and five became CVEs.
Who can join the Critical Infrastructure Defense Program?
Anthropic's Critical Infrastructure Defense Program is for companies that build security products or services for operational technology such as power grids, water systems and transport. Founding partners include Accenture, CrowdStrike, Dragos, Palo Alto Networks and Rockwell Automation. Anthropic starts with a small group of providers, and other companies can register interest through a form.
How is the Cyber Mission different from the Cyber Verification Program?
The Cyber Verification Program, expanded on October 6, gives verified security teams access to Claude models with fewer cyber blocks. The Cyber Mission is the wider umbrella announced two days later: it adds the free OSS Scanner for open-source maintainers and the Critical Infrastructure Defense Program, and lists the verification program as one of its parts.

Try it

https://github.com/anthropics/oss-scanner

Sources · 3 outlets

Tags

  • anthropic
  • claude
  • cybersecurity
  • oss-scanner
  • open-source
  • vulnerability-scanning
  • critical-infrastructure
  • claude-mythos
  • project-glasswing

← All releases · Learn AI