BuildNot yet confirmed elsewhere1 publisher3 min readPublished
Anthropic's Cyber Mission targets the months between finding a bug and fixing it
Anthropic's Cyber Mission puts Claude models, engineers and funding behind bug fixing, after Glasswing finds often waited months for a patch. Its free OSS Scanner sends unreviewed reports that Anthropic expects to be over 90% accurate, so it suits maintainers who have time to verify them.
The Engineer · Build desk

What happened
- The first program, the Critical Infrastructure Defense Program, gives Claude models, on-site engineers and threat research to the vendors and consultancies that tell utilities which fixes to apply.
- OSS Scanner is a free, opt-in service that periodically scans enrolled open-source projects and returns a proof of concept, an explanation and, where available, a suggested fix.
- Anthropic names four foundations it has funded: the Python Software Foundation, the Apache Software Foundation, Alpha-Omega, and OpenSSF, by way of the Linux Foundation.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Maintainers now have to choose between faster model reports they verify themselves and slower human-verified disclosure. Enrolling in the scanner adds triage work before it saves any.
- cost At the stated accuracy floor, one scanner report in ten is wrong. Volunteer teams with no security budget spend the hours working out which one.
- constraint Utilities and OT operators reach these models only through existing providers. Their access depends on whether their vendor or consultancy is one of the 11 founding partners.
The design starts from Anthropic's own post-mortem. According to a dev.to breakdown of the announcement, Anthropic says Project Glasswing found many vulnerabilities, and concedes that it did not cut cyber risk enough [13]. Under Glasswing, months often passed between a bug being found and being fixed [2]. The slow steps it names are triage, prioritization and patching. All three still depend on people [3].
The infrastructure program goes after those steps directly. Operational technology in grids and water systems often cannot be taken offline to patch, so known vulnerabilities stay open for years [4]. That equipment is proprietary, changes to it are risky, and a mistake can take down a plant [18]. The hard decision is which fix to apply to a running system. Anthropic is putting models and on-site engineers inside the firms that already make that decision for utilities, and it is working through those firms' existing relationships instead of selling to utilities itself [5][7]. I think vendors are the right channel for this work, because they already hold the service contracts and the equipment knowledge. The founding list names 11 companies [19]. Four are OT specialists: Dragos, Nozomi Networks, Rockwell Automation and Hitachi [6]. The program extends a June effort for US state, local, tribal and territorial governments that has reached more than half of US states [8].
The open-source half is a different tool. OSS Scanner is modeled on Google's OSS-Fuzz, with model-driven discovery in place of fuzzing [10]. It finds bugs. Each report does carry a proof of concept and, where one exists, a suggested fix [9], so some of the patch work arrives with the finding. Reports go out without human review, and Anthropic says it expects a true-positive rate above 90% [11]. At that floor, one report in ten is wrong [20]. Separating that one from the other nine is triage, the step Anthropic calls the bottleneck. On most projects the job falls to small volunteer teams with no security budget, the breakdown says [22]. Anthropic handles this by scoping. Limiting the scanner to projects that can keep up is good engineering, and it was stated up front. Projects without that capacity keep getting human-verified reports through Anthropic's coordinated vulnerability disclosure process [12].
For a maintainer, the direct offers are scanner enrolment and a free Claude Max subscription. Maintainers have to apply to Claude for Open Source for the subscription [17]. The rest of the money goes through foundations. Anthropic names four it has funded: the Python Software Foundation, the Apache Software Foundation, Alpha-Omega, and OpenSSF, by way of the Linux Foundation [15]. The Defender Advantage Fund, launched in August, backs pilot programs and pays to keep OSS Scanner free [16]. The breakdown does not give dollar amounts for any of these grants. Security professionals who qualify for the expanded Cyber Verification Program, which now includes Glasswing, get more capable models with reduced blocking classifiers for defensive work [14].
Anthropic forecasts that within two years AI will favor defense [21]. As described so far, infrastructure operators get help with fixes through 11 partner firms [19]. Open-source projects get a suggested patch attached to a model-written report [9].
What to watch
- Whether Anthropic publishes OSS Scanner's measured true-positive rate against its stated expectation of above 90%.
- Dollar figures for the foundation grants and the Defender Advantage Fund, which would show how much patching labour the funding can buy.
- Whether the Critical Infrastructure Defense Program adds partners beyond the founding 11 or opens a direct route for utilities.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence40
- Adoption20
- Hype gap+10
- Incentives55
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Anthropic launched the Anthropic Cyber Mission, a long-term program that puts frontier models, engineers, and funding behind the defenders of critical infrastructure and open-source software.
- [2]
Anthropic says that under Project Glasswing, its earlier vulnerability-finding effort, months often passed between a bug being found and being fixed.
- [3]
The bottleneck is no longer discovery; it is triage, prioritization, and patching, and all three still depend on people.
- [4]
Operational technology in power grids, water systems and transport networks often cannot be taken offline to patch, so known vulnerabilities stay unresolved for years.
- [5]
The first launch under the Cyber Mission is the Critical Infrastructure Defense Program (CIDP), which brings frontier Claude models, on-site engineers, and threat research to trusted providers (consultancies, security vendors, equipment makers) that tell utilities what is exposed and which fixes to apply on running systems.
- [6]
CIDP founding partners: OT specialists Dragos, Nozomi Networks, Rockwell Automation, Hitachi; Palo Alto Networks, CrowdStrike; consultancies Accenture, Booz Allen, Deloitte, PwC; and Insane Cyber.
- [7]
Anthropic is explicitly not going direct to utilities; it is working through the companies that already hold those relationships.
- [8]
CIDP builds on a program launched in June for US state, local, tribal, and territorial governments, which has since reached more than half of US states.
- [9]
OSS Scanner is a free, opt-in service for open-source projects; enrolled projects get periodic security scans from Anthropic's strongest models, and each report includes a proof of concept, an explanation of the vulnerability, and a suggested fix where one is available.
- [10]
OSS Scanner is explicitly inspired by Google's OSS-Fuzz, but for model-driven vulnerability discovery instead of fuzzing.
- [11]
OSS Scanner reports are model-generated and sent without human review; Anthropic expects a true-positive rate above 90% and commits to improving it.
- [12]
OSS Scanner is aimed at projects with the capacity to keep up with findings; projects that cannot still get human-verified reports through Anthropic's coordinated vulnerability disclosure process.
- [13]
The announcement credits Glasswing with uncovering many vulnerabilities but admits it did not achieve a sufficient reduction in cyber risk.
- [14]
Glasswing has been merged into the expanded Cyber Verification Program, which gives qualifying security professionals access to more capable models with reduced blocking classifiers for defensive work.
- [15]
Anthropic says it has funded the Python Software Foundation, Alpha-Omega, OpenSSF through the Linux Foundation, and the Apache Software Foundation.
- [16]
The Defender Advantage Fund (0xDAF), launched in August, backs pilot programs and keeps OSS Scanner free.
- [17]
Maintainers can apply to Claude for Open Source for free Claude Max subscriptions.
- [18]
Securing a substation differs from securing a web app: the equipment is proprietary, changes are risky, and a mistake can take down a plant.
- [19]
The CIDP founding partner list names 11 companies.
- [20]
At a 90% true-positive rate, 10% of scanner reports, one in ten, would be wrong.
- [21]
Anthropic forecasts that in two years AI will favor defense.
- [22]
Most open-source software is maintained by small volunteer teams with no security budget.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toAnthropic's Cyber Mission: What It Actually Contains
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Entities
- AnthropicFollow
- ClaudeFollow
- Anthropic Cyber MissionFollow
- Project GlasswingFollow
- OSS ScannerFollow
- Critical Infrastructure Defense ProgramFollow
- Cyber Verification ProgramFollow
- OSS-FuzzFollow
- DragosFollow
- Nozomi NetworksFollow
- Rockwell AutomationFollow
- Palo Alto NetworksFollow
- CrowdStrikeFollow
- Python Software FoundationFollow
- OpenSSFFollow
- Alpha-OmegaFollow
- Apache Software FoundationFollow