Anthropic introduced the Cyber Mission on October 8, expanding its cybersecurity work into two distinct defensive programs: support for operators of critical infrastructure and recurring vulnerability scans for open-source software. The initiative follows its earlier Project Glasswing and an expanded Cyber Verification Program, but focuses more directly on getting frontier-model capabilities into the hands of organizations responsible for fixing vulnerable systems. The company presents this as a long-term commitment, not as proof that AI has already reduced overall cyber risk.
The Critical Infrastructure Defense Program, or CIDP, initially targets operational technology used in electricity, water, transport, industrial plants and government systems. Such environments often contain controllers and software that cannot be patched on the same schedule as ordinary enterprise applications. Anthropic plans to provide Claude models, on-site engineers and threat research through a group of established providers rather than offering unrestricted direct access to every operator. Its 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
The second launch, OSS Scanner, is an opt-in service for maintainers of critical open-source projects. Anthropic says enrolled projects will receive periodic scans at no charge, with each report including a possible exploitation demonstration, an explanation and a suggested repair when available. Unlike the coordinated disclosures made during Project Glasswing, these reports are sent without human review. Anthropic expects a true-positive rate above 90%, but explicitly warns that individual findings, including severity assessments, can be wrong. That forecast is not an independently measured production outcome.
The company is deliberately separating the needs of maintainers who can process a large stream of machine-generated findings from those who need carefully verified disclosures. Projects unable to triage high volumes will still be eligible for human-reviewed reports through its existing coordinated disclosure process. Anthropic says future work will address faster triage and patching, while funding from its Defender Advantage Fund helps keep OSS Scanner free. It also points maintainers to Claude for Open Source and its Cyber Verification Program for additional defensive access.
A central obstacle is the difference between finding a vulnerability and safely eliminating it. Industrial systems may need long maintenance windows, safety approvals and hardware-vendor involvement before a patch can be applied. Open-source projects, meanwhile, can be overwhelmed by low-quality reports. Anthropic itself says Glasswing uncovered many flaws without yet demonstrating a sufficient reduction in overall risk. Axios independently reported the new program and highlighted the same operational challenge for critical-infrastructure defenders.
The launch therefore establishes concrete programs and named partners, but not a validated reduction in incidents or time to remediation. The most important results to watch are whether scanner findings are reproducible, whether maintainers can handle their volume, and whether industrial operators can turn model-assisted detection into verified fixes without compromising availability or safety.