Citation and evidence

Anthropic Cyber Mission

4 min full readUpdated 8 references

This article's verification

Report a problem with this article

More

Use this article

Raw MarkdownExplore connections

Improve this page

Suggest editRevision history

Topics

AI in CybersecurityAnthropic

Cite this article

Anthropic Cyber Mission is a cybersecurity initiative announced by Anthropic on October 8, 2026. Its initial work covers critical infrastructure and open-source software through the Critical Infrastructure Defense Program (CIDP) and OSS Scanner. The mission combines model access with engineering support, research, and funding.[1]

Critical Infrastructure Defense Program

CIDP brings frontier Claude models, on-site engineers, and threat research to providers that help defend operational technology (OT). Its initial scope includes the systems behind power grids, water utilities, transportation, and government services. Anthropic began with a small group of providers to test which approaches work in these environments.[1]

The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.[1]

OT includes programmable equipment that monitors or controls physical processes. NIST's guidance distinguishes its performance, reliability, and safety requirements from ordinary information systems. Industrial control, building automation, and transportation are examples of OT applications.[2]

OSS Scanner

OSS Scanner periodically examines enrolled open-source projects at no cost. Its reports come directly from models, including Claude Mythos, without human review or triage. A report contains a reproducer, a vulnerability explanation, and a candidate patch when available; it may also identify the change that introduced the bug.[3]

Anthropic reported checking an early scanner pipeline against 97 high- or critical-severity findings across 48 projects. Of these, 85 met its coordinated disclosure standard, 11 were real but duplicated known issues or other findings, and one was invalid. This was a limited validation sample, not a guaranteed accuracy rate for every scan. Anthropic also reported that severity ratings and assumptions about a project's threat model can be wrong.[3]

The service targets established projects important to infrastructure or user security. Anthropic considers applications individually and verifies that an applicant is a core maintainer. The FAQ says it is intended for teams able to handle additional reports beyond the verified high- and critical-severity findings they already receive.[4]

Enrollment and scanning environment

Maintainers enroll through a pull request to the official anthropics/oss-scanner repository, adding a directory under projects/<name>/. The repository documents these configuration fields:[5]

Field or filePurpose
repoRepository to scan; a branch can be specified
primary_contactAddress for findings and build errors
dockerfile or adjacent DockerfileBuild instructions and dependencies
threat_model or adjacent threat_model.mdOptional project-specific security assumptions and reporting guidance
auto_ccsOptional additional recipients
pgpOptional encryption key; cannot be combined with auto_ccs
disabledPauses reports when set to true

Expanded article table

The scanner builds a project in an isolated virtual machine with network access, then performs the audit without Internet access. Contact addresses in the public configuration are publicly visible, so the repository recommends using an address suitable for publication.[5]

Disclosure and opting out

Unreviewed OSS Scanner findings do not automatically start a 90-day coordinated disclosure deadline. If Anthropic later validates a report through its ordinary coordinated vulnerability disclosure process, that process may start a deadline when the maintainer is notified of human validation.[4]

Maintainers can pause reports with disabled: true or withdraw their project through a pull request. Opting out returns the project to Anthropic's standard human-verified disclosure process. The FAQ says findings are held in a restricted cloud environment available to the Anthropic security staff who need them.[4]

The Defender Advantage Fund, styled 0xDAF, supports pilots and the free OSS Scanner service.[1] Anthropic announced the fund on August 21, 2026, with $35 million in Claude credits. Its stated priorities are repairing vulnerabilities in widely used open-source projects, automating scanning and patching, and testing approaches that prevent classes of vulnerabilities. The initial plan uses a small number of larger pilot grants.[6]

The Anthropic Cyber Verification Program governs access to advanced cyber capabilities and reduced blocking classifiers for qualifying security professionals. Its October 6 expansion introduced Defense, Red Team, and Specialized Access tiers. Project Glasswing was integrated into that offering, with existing Glasswing members transitioning to Specialized Access. Authorization to test systems and the required security controls remain conditions of access.[7]

OSS Scanner is distinct from Claude Security, Anthropic's commercial code-scanning and patching product for enterprises. OSS Scanner focuses on open-source maintainers and Anthropic covers the scanning cost.[3]

Research context

AI in cybersecurity covers several different tasks. For example, CyberGym primarily evaluates whether an agent can reproduce a known vulnerability from its description and codebase. Its authors validate generated tests against vulnerable and patched versions. Such a reproduction benchmark measures a different outcome from an operational program's ability to get newly found problems repaired.[8]

References

  1. ^1 ^2 ^3 ^4Anthropic. Introducing the Anthropic Cyber Mission. October 8, 2026.
  2. ^Stouffer, Keith A., et al. Guide to Operational Technology (OT) Security. NIST SP 800-82 Revision 3. September 28, 2023. DOI: 10.6028/NIST.SP.800-82r3.
  3. ^1 ^2 ^3Anthropic Frontier Red Team. Launching an opt-in vulnerability-finding service for open-source software. October 8, 2026.
  4. ^1 ^2 ^3Anthropic Frontier Red Team. OSS Scanner: overview and FAQ. Accessed October 10, 2026.
  5. ^1 ^2Anthropic. OSS Scanner repository and enrollment documentation. Accessed October 10, 2026.
  6. ^Anthropic. Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders. August 21, 2026.
  7. ^Anthropic. Expanding the Cyber Verification Program. October 6, 2026.
  8. ^Wang, Zhun, et al. CyberGym: Evaluating AI Agents' Real-World Cybersecurity Capabilities at Scale. arXiv:2506.02548v3. March 24, 2026. DOI: 10.48550/arXiv.2506.02548.

Improve this article

Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.

1 revision · v1 · 898 words · full history

Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify

Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here

Reviewer note: Independent full-article review against 8 cited primary and academic sources, October 10, 2026. Checked subject identity, specifications, availability, benchmark conditions and limitations.

Cite this page: AI Wiki. "Anthropic Cyber Mission." aiwiki.ai, updated 10 Oct 2026, fact-checked 10 Oct 2026. CC BY 4.0. https://aiwiki.ai/wiki/anthropic_cyber_mission

Suggest edit