Anthropic has launched what it calls the Anthropic Cyber Mission, “a long-term commitment to securing the systems everyone depends on.” The 8 October 2026 announcement starts with two programs: one for the operational technology behind power, water and transport, and one for open-source software.
The framing is explicitly dual-use. Anthropic writes that “frontier models can be misused to exploit vulnerabilities and conduct cyber operations,” and that it is now “easier than ever to find vulnerabilities, but verifying, prioritizing, and fixing these findings remains challenging.”
OSS Scanner: free, opt-in, and unreviewed
OSS Scanner is modeled on Google’s OSS-Fuzz, but uses language models instead of fuzzers. Enrolled projects get periodic scans “by our strongest models (including Claude Mythos),” at no cost.
The key design choice: reports are “fully model-generated, without human review or triage.” Each one includes a self-contained reproducer, an explanation (with a bisection to the introducing commit where possible) and a candidate patch when one is available. Anthropic says that means faster delivery but also that “it is possible reports will be incorrect or invalid,” for example with an inflated severity. It says it expects a true-positive rate above 90%.
The service is aimed at projects with the capacity to handle that volume. Projects without it will keep getting human-verified reports through Anthropic’s existing coordinated disclosure process.
The numbers behind it
All figures are Anthropic’s. Over six months, it says, its models found “over 29,000 candidate vulnerabilities,” of which about 6,000 were manually reviewed. Nearly 5,000 unverified reports have already gone to maintainers who asked for everything.
To validate an early version, Anthropic had penetration testers check 97 critical and high-severity findings across 48 projects. Eighty-five (88%) met its disclosure bar; 11 of the remaining 12 were real but duplicates; one was a false positive. Maintainer quotes in the post include wolfSSL’s Todd Ouska: “of the 74 reports we received, all but two were valid, and five became CVEs.” PostgreSQL, OpenSSL and HotCRP maintainers are also quoted favourably.
How to enroll: core maintainers submit a pull request to Anthropic’s OSS Scanner GitHub repository using the project template. Eligibility follows criteria similar to OSS-Fuzz, meaning critical impact on infrastructure and user security, decided case by case.
Critical Infrastructure Defense Program
The second program brings Claude models, on-site Anthropic engineers and threat research to the firms that secure operational technology for utilities and manufacturers. The founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic calls it a first step with “a small cohort of providers,” and companies that build OT security products can register interest.
The announcement also notes that Project Glasswing has been folded into the expanded Cyber Verification Program, which Anthropic says “gives many more defenders access to our most capable models.”
What maintainers should weigh
Opting in trades human filtering for speed. A project that enrolls should be ready to triage reports itself, check each reproducer before acting, and treat severity labels as a starting point. Anthropic’s own forecast is that AI will favour defense in about two years, “but in the near term, that may not be true.”

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.