Anthropic's Claude Now Hunts Security Bugs in Critical Infrastructure and Open Source
Anthropic is deploying Claude, engineers, and threat research to defend power grids, water utilities, and open-source code through two new programs.
- Anthropic launched the Cyber Mission, targeting critical infrastructure and open-source software security.
- Critical Infrastructure Defense Program partners include CrowdStrike, Palo Alto Networks, Dragos, Rockwell, Accenture, Deloitte, PwC, Booz Allen, Hitachi.
- OSS Scanner gives opted-in projects free periodic scans from Claude Mythos with patches included.
- Reports ship model-generated without human review; Anthropic targets above 90% true-positive rate.
- Project Glasswing surfaced 29,000+ candidate vulnerabilities but only 6,000 were human-triaged.
- Early validation: 88% of 97 critical findings across 48 projects met formal disclosure bar.
Anthropic launches AI security programs for infrastructure and open source
Anthropic has launched its Cyber Mission, combining two defensive security programs. The Critical Infrastructure Defense Program supports companies that secure operational technology, while OSS Scanner provides free, automated vulnerability reports to eligible open-source projects.
Anthropic argues that advanced cyber models are reaching attackers faster than defensive tools are reaching security teams. Its new programs aim to widen defensive access while addressing a growing operational problem: models can discover vulnerabilities faster than people can validate, disclose, and patch them.
Claude enters industrial networks
Operational technology, commonly called OT, includes the hardware and software that control power grids, water systems, factories, transit networks, and other physical processes. These environments often require continuous operation, scheduled maintenance windows, and extensive safety testing. A known vulnerability may therefore remain unresolved long after a patch becomes available.
The Critical Infrastructure Defense Program will distribute Anthropic’s most capable Claude models through established OT security providers. Founding partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
Participating partners receive three forms of support:
- Access to frontier Claude models, Anthropic’s highest-capability systems
- On-site Anthropic engineers working with partner security teams
- Threat research from Anthropic’s internal red-team investigations
Anthropic’s existing public-sector cyber program provides an earlier example of this approach. The company says it has offered model access and technical support to more than half of US states, along with several large public infrastructure operators. Reported uses include code scanning, patch development, incident response, and red-team exercises.
Model-written reports reach maintainers directly
OSS Scanner periodically audits enrolled open-source projects with Anthropic’s strongest models at no cost. Google’s OSS-Fuzz finds defects by feeding programs unexpected inputs and monitoring the resulting failures. Anthropic’s service applies large language models to source-code review.
Each report can include an explanation of the vulnerability, a proof-of-concept exploit, a candidate patch, and a version-history bisection identifying the likely commit that introduced the bug. Those artifacts can reduce the work required to reproduce a finding and locate the affected code.
Reports leave Anthropic without human review or triage. This design increases scanning volume and shortens delivery time while passing validation work to maintainers. Anthropic warns that reports may be incorrect, duplicative, or otherwise invalid, and says it expects a true-positive rate above 90%.
Ninety-seven reports test the error rate
Expert penetration testers evaluated 97 critical and high-severity reports from an early version of OSS Scanner across 48 projects. Anthropic reported the following results:
- 85 reports, or 88%, qualified for the formal disclosure process.
- 11 reports described real vulnerabilities that had already been reported.
- One report was a false positive.
Counting duplicates, 96 of the 97 reports corresponded to real vulnerabilities. The selected sample establishes performance for that test alone; accuracy may vary by language, codebase, vulnerability class, and project maturity.
Twenty-nine thousand findings strain human review
Anthropic’s Project Glasswing, an earlier open-source vulnerability research effort, identified more than 29,000 candidate vulnerabilities during a six-month period. Human reviewers manually assessed about 6,000. Manual validation now constrains how quickly Anthropic can send useful findings to maintainers.
Maintainers have requested nearly 5,000 unvalidated reports from the project, according to Anthropic. That demand reflects the practical value of early warning, though every raw report consumes maintainer time and may require exploit reproduction, severity assessment, patch testing, and coordinated disclosure.
Model performance has also improved rapidly. Anthropic says large language models increased their detection rate on CyberGym, an academic vulnerability-finding benchmark, from below 20% to above 85% over roughly a year. Early OSS Scanner participants include PostgreSQL, OpenSSL, wolfSSL, and HotCRP.
wolfSSL reported that 72 of 74 findings it received were valid and that five received CVE identifiers. Those results provide an encouraging project-level example, though broader performance will become clearer as the service expands to codebases with different languages, architectures, and review practices.
Security work shifts at three points
- Direct model output. OSS Scanner delivers findings before human triage, reducing reporting delays and increasing the volume that maintainers must assess.
- Remediation context. Reports may include candidate patches, proof-of-concept exploits, and the likely introducing commit, giving maintainers more than a scanner alert or suspicious code location.
- Embedded OT support. The infrastructure program pairs model access with Anthropic engineers and established security providers, integrating Claude into active assessments and remediation work.
Exploit speed collides with patch timelines
Anthropic forecasts that AI could favor defenders within two years by detecting defects earlier and helping developers produce safer code. Current conditions remain difficult: models can help generate exploits in minutes, while verification, disclosure, patch review, release engineering, and deployment still require substantial human effort.
Operational technology extends those timelines. Anthropic says Project Glasswing findings often took months to resolve. Industrial patches may also need to wait for maintenance shutdowns, equipment recertification, or safe deployment windows. The company says remediation has taken decades in rare cases.
Maintainers and infrastructure operators therefore remain responsible for confirming exploitability, reviewing generated patches, testing for regressions, and coordinating deployment. Higher discovery rates increase the value of those processes and the workload placed on the teams running them.
Four routes into the programs
Access varies by role, and the infrastructure program primarily reaches operators through Anthropic’s security partners.
| Offering | Intended users | Access path |
|---|---|---|
| OSS Scanner | Core maintainers of high-impact open-source projects | Submit a pull request to the Anthropic repository linked from the OSS Scanner announcement. Eligibility resembles OSS-Fuzz criteria and focuses on projects with significant infrastructure or user-security impact. |
| Claude for OSS | Eligible open-source maintainers | Apply separately for a free Claude Max 20x subscription. |
| Critical Infrastructure Defense Program | OT security vendors, systems integrators, and equipment manufacturers | Register interest through the Cyber Mission announcement. Infrastructure operators participate through program partners. |
| Cyber Verification Program | Qualified defensive security teams | Apply for higher-capability Claude access with safety classifiers adjusted to reduce interruptions during legitimate defensive work. |
Measure the path from report to remediation
The programs can be evaluated through operational results that extend beyond vulnerability benchmarks:
- Precision among reports delivered to maintainers
- Time required to validate and triage each report
- Acceptance and regression rates for model-generated patches
- Time from confirmation to disclosure and release
- Time required to deploy fixes in operational environments
Together with Claude Security, the Cyber Mission places Anthropic’s models inside the workflows that convert findings into deployed fixes. Its results will depend on report quality, maintainer capacity, partner execution, and safe OT deployment, all constraints that discovery benchmarks leave unresolved.