i
News
News · 2026-10-08

Anthropic expands cyber support for infrastructure and open source

@neuronium_ai @neuronium_ai

Anthropic is extending its cyber work from model access to hands-on support for critical infrastructure operators and open-source maintainers. Its new Cyber Mission pairs advanced Claude models with engineering expertise, threat research and funding, while a free scanner will send open-source projects vulnerability reports generated by models and not reviewed by experts. The announcement matters because finding flaws is getting easier; validating and fixing them remains slow.

Cover: Anthropic expands cyber support for infrastructure and open source

From finding flaws to fixing them

Project Glasswing showed that advanced models can help uncover vulnerabilities across widely used software. But discovery is only one part of defense: teams still have to verify findings, decide what matters and make fixes. Anthropic says those steps remain difficult, especially where systems cannot be taken offline for updates.

Earlier this week, Anthropic expanded its Cyber Verification Program to give more defenders access to its most capable models. The new Critical Infrastructure Defense Program adds engineering support and threat research for organizations protecting systems such as power grids, water utilities, factories and transport networks.

These operational technology (OT) systems often stay in service for decades. They rely on equipment from different vendors, and changing a live system can carry operational risks. Anthropic is starting with a small group of partners, several of which are already using Claude to find and address vulnerabilities with their customers.

The initial partners span consulting firms, cybersecurity providers and equipment makers:

Accenture, Booz Allen, Deloitte and PwC
CrowdStrike, Dragos, Insane Cyber, Nozomi Networks and Palo Alto Networks
Hitachi and Rockwell Automation

Anthropic previously launched a cyber defense program for U.S. state, local, tribal and territorial governments in June. Since then, it has offered Claude models and technical support to more than half of U.S. states and some of the country’s largest critical infrastructure operators.

The company says that support has helped speed up code review, patching, incident response and security testing. The new program is an attempt to bring more of that work to infrastructure defenders, while learning which approaches can be used in real operating environments.

A faster route for open-source reports

Project Glasswing also involved reviewing hundreds of widely used open-source projects. Anthropic says specialists assessed many potential vulnerabilities and privately reported confirmed issues to maintainers under coordinated disclosure practices.

Some maintainers asked to receive every model finding, including those not yet checked by a specialist. Anthropic’s response is OSS Scanner, an opt-in service modeled on Google’s OSS-Fuzz. Participating projects will receive periodic scans by Anthropic’s most capable models at no charge.

Reports will describe how a flaw could be exploited, explain the issue and suggest a fix when possible. They will be generated by models and sent without expert review, so they may contain errors, including an inaccurate severity assessment. Anthropic expects more than 90% of findings to be correct and says it plans to improve both detection and the quality of suggested fixes.

The service is intended for projects whose teams can handle incoming reports. Anthropic will continue to send specialist-reviewed findings to projects that need that process.

The scanner is one part of a broader open-source effort. Anthropic plans to expand it, automate more of the work involved in sorting reports and preparing fixes, and study safer software architectures and programming practices. It has allocated funds to the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. It has also supported Akrites and Gold Eagle, which coordinate vulnerability reports from different sources.

Maintainers can apply for free Claude Max subscriptions through Claude for Open Source, or seek expanded cyber access through the Cyber Verification Program.

The bottleneck is still people

Anthropic’s case for the Cyber Mission rests on a mismatch: AI can make exploitation cheaper, while verifying, disclosing and fixing vulnerabilities still takes time and human effort. In Project Glasswing, months often passed between discovering a vulnerability and fixing it. For OT systems, a patch may have to wait until it can be safely applied to equipment in operation; in rare cases, that wait can stretch to decades.

I think the most important detail is not the promise of faster discovery, but the decision to send some reports without expert review. That could help maintainers who have the capacity to triage more findings, while increasing the burden on teams already short of time. Anthropic’s expectation that more than 90% of findings will be correct is a forecast, not evidence that projects can absorb the reports at that rate.

The program’s limits are just as relevant. Anthropic says it will begin with a small group of infrastructure providers, and that AI cannot solve every problem in protecting critical systems. What I’d want to know is how the company will judge whether the effort is reducing risk: a vulnerability report is useful only if someone can verify it, prioritize it and safely make the repair.

Anthropic expects the Cyber Mission to change as public and private organizations learn which approaches work. It plans to add partners and industries in the coming months, share lessons including unsuccessful results, and expand its work on open-source software and the wider supply chain. The underlying test is whether more model-generated findings lead to faster, safer repairs—not simply more findings to process.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X