Eigen RadarAI
Analysis

Anthropic’s Cyber Mission pairs infrastructure defenders with free open-source security scans

Anthropic has launched Cyber Mission, a long-term effort to help defenders secure systems the public relies on. It starts with a Critical Infrastructure Defense Program backed by 11 founding partners, aimed at power, water and transportation systems, and Open Source Software (OSS) Scanner, a free opt-in service that scans open-source projects on a recurring basis. Anthropic says the scanner’s reports are model-generated and not reviewed by humans, so maintainers need capacity to triage them.

Artificial Intelligence··Midday
A daylight water-plant hall with blue pipes connected to a pump.

Anthropic opens Cyber Mission with an infrastructure program and an open-source scanner

Anthropic, the AI company behind Claude, announced Cyber Mission on October 8 as a long-term effort to help defenders secure systems the public relies on. It begins with two programs: a Critical Infrastructure Defense Program backed by 11 founding partners, and Open Source Software (OSS) Scanner, a free opt-in service that runs regular security scans of open-source software.[1], [2]

The infrastructure program covers defensive work in areas including power, water, transportation and government systems. Anthropic describes a mix of advanced models, engineers who work alongside customers, threat research and expertise in operational technology, the control systems that run physical plants.[1]

Named partners include the industrial and security companies Rockwell Automation, Dragos, Nozomi Networks, CrowdStrike and Palo Alto Networks. The founding group also includes Accenture, Booz Allen, Deloitte, Hitachi, Insane Cyber and PwC.[1]

Industrial systems built to run for decades often cannot be taken offline to patch

Operational technology covers the controllers and industrial networks that were built to run for decades. These systems often cannot be taken offline to patch, which makes each change depend on being applied safely to running machinery.[1]

Cyber-physical systems receive particular attention because a software incident in them can affect a physical service. The program therefore looks at the digital and physical sides of these environments together.[1]

The scanner’s reports come from a model and are not reviewed by humans

In the open-source program, maintainers can opt in to free recurring security scans. OSS Scanner, which Anthropic describes as inspired by Google’s OSS-Fuzz, writes reports describing a potential vulnerability and adds proof-of-concept material and a suggested fix where it can.[1]

Anthropic says these reports are model-generated and not reviewed by humans. A finding can be wrong or carry an unsuitable severity rating, so maintainers need the capacity to assess and triage reports instead of treating each output as a verified defect. For findings that people have verified, the company says coordinated disclosure continues separately.[1]

Financial support for organizations in the Python and Linux ecosystems and for Apache-related open-source work is also part of the announcement. A previously established defensive fund and model access for maintainers continue, and maintainers can apply for free Claude Max access through Claude for Open Source.[1]

References

  1. News sourceAnthropicAnthropic launches Cyber Mission for critical infrastructure and open source↩1↩2↩3↩4↩5↩6↩7↩8
  2. News sourceUnite.AIAnthropic opens Cyber Mission with an infrastructure defense program and free open-source scans↩