Anthropic PBC introduced the Anthropic Cyber Mission, a two-part effort aimed at securing the software and industrial systems that underpin everyday life. The first piece, the Critical Infrastructure Defense Program, pairs Anthropic's frontier models and onsite engineers with the security providers that utilities already consult. The second, OSS Scanner, gives open-source projects free periodic vulnerability scans from the company's strongest models.

The defense program targets operational technology inside plants, substations and water systems. Equipment in those environments is built to run for decades and often cannot be pulled offline for a patch, so known flaws can persist for years. Eleven outside providers joined as founding partners, and Anthropic said some are already using Claude to remediate vulnerabilities and to help their customers do the same. More partners and sectors are expected to join in the coming months.

Andrew Turner, president of commercial cyber at Booz Allen, described operational technology as the next frontier for autonomous AI-enabled attacks. In remarks released with the announcement, he said the key questions are how much control artificial intelligence can gain over an industrial process and how quickly it can do so. Commercial terms were not disclosed. Axios reported that Anthropic has not said whether partners receive free model access or who pays for the computing, and raised questions about how partners will test and deploy fixes without disrupting utility operations.

OSS Scanner emerged from a backlog in Anthropic's own disclosure work. Over six months, its models surfaced more than 29,000 candidate vulnerabilities in widely used software, of which staff manually reviewed about 6,000. Maintainers who received early reports increasingly asked for the full unreviewed batch, including proposed patches, and nearly 5,000 such reports have been sent. The service was modeled on Google LLC's OSS-Fuzz, which runs fuzzers against open-source code.

Each report includes a self-contained reproducer. Anton Arapov of the OpenSSL Corporation, an early tester, said a report containing a working exploit essentially completes the job for an engineer. Where the model can manage it, a candidate patch accompanies the write-up, and a bisection of the code history identifies when the flaw appeared.

Reports go directly to maintainers without human review to speed delivery, and Anthropic acknowledged some will contain errors such as incorrect severity ratings. Before expanding access, expert penetration testers who vet the company's coordinated disclosures examined 97 critical and high-severity findings from an early version across 48 projects and cleared 85 for disclosure. Of the remaining 12, all but one were real bugs that duplicated known issues or other scan findings. WolfSSL Inc. said all but two of the 74 reports it received in early trials were valid, and five became CVEs.

Core maintainers enroll by submitting a pull request to an Anthropic GitHub repository, with eligibility following the OSS-Fuzz standard of critical impact on infrastructure and user security and decisions made case by case. Projects lacking staff to handle raw findings still receive human-verified reports through Anthropic's existing disclosure process. The Defender Advantage Fund, established in August, keeps the scanner free. Anthropic has also funded the Python Software Foundation, the Apache Software Foundation, and Alpha-Omega and OpenSSF through the Linux Foundation. Both launches draw on Project Glasswing, which gave vetted organizations access to Claude Mythos from April until it was folded into an expanded Cyber Verification Program earlier this week.

More software news from TechManNews.