Skip to content
D-CSIL

AI News · 2026-10-10 · 8:00 AM CT

Anthropic is giving open-source projects free AI security scans

TL;DR

Anthropic launched its Cyber Mission on October 8 — a long-term commitment to 'securing the systems everyone depends on,' putting frontier Claude models in the hands of defenders. Open-source maintainers can opt in to OSS Scanner for free periodic vulnerability scans, each with a proof of concept, an explanation, and a suggested fix. A parallel Critical Infrastructure Defense Program sends frontier models and on-site engineers to 11 founding partners protecting power grids, water systems, and transportation.

Close-up of a monitor displaying cybersecurity code
Photo: Tima Miroshnichenko / Pexels

Two programs, one mission

On October 8, Anthropic launched the Cyber Mission with two opening programs: the Critical Infrastructure Defense Program (CIDP) for operational technology — power grids, water utilities, factories, transportation networks — and OSS Scanner for open-source software. The company's argument is blunt: frontier models can now be misused to exploit vulnerabilities and conduct cyber operations, while the defenders of critical infrastructure and the open-source community have decades of security experience but face severe resource shortages.

Anthropic forecasts that in two years, AI will favor defense — it will be easier to catch bugs before they ship and write fundamentally secure software from scratch — but concedes that in the near term, that may not be true. Right now, finding a bug is getting cheaper while verifying, disclosing, and fixing it is still slow and depends on people.

OSS Scanner: free bug hunting for your project

OSS Scanner is a free, opt-in service, inspired by Google's OSS-Fuzz, that gives enrolled open-source projects periodic scans from Anthropic's most capable models. Each report includes a proof of concept showing how the bug could be exploited, an explanation of the flaw, and a suggested fix where one is available.

The trade-off is explicit: reports are model-generated and sent without human review, which buys faster, more frequent scans at the price of some reports being wrong — Anthropic calls out incorrect severity ratings as an example. It expects a true-positive rate above 90% and says it will work to improve both that and fix quality over time. The service is aimed at projects with the capacity to keep up with surfaced findings; for everyone else, Anthropic continues human-verified disclosures under its coordinated vulnerability disclosure policy.

It is funded by the Defender Advantage Fund (0xDAF), which Anthropic launched in August. The company also announced funding for the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation — plus groups that coordinate vulnerability reports so maintainers don't get overwhelmed. Open-source maintainers can also apply for free Claude Max subscriptions through Claude for Open Source.

The infrastructure half

The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers, and Anthropic's threat research to the trusted providers that protect operational technology. Its 11 founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Several are already working with Claude to fix vulnerabilities and help customers do the same.

The hard part is physical: these systems are built to last for decades and often can't be taken offline to patch, so known vulnerabilities can stay unresolved for years — in rare cases a fix may have to wait until it can be applied safely to running machinery. Anthropic's first step is a small cohort of providers, learning which strategies actually work in live industrial environments. This builds on Project Glasswing, which scanned hundreds of widely used open-source projects and was merged earlier that week into the expanded Cyber Verification Program — and on a June program that has since offered frontier Claude models and technical support to more than half of all US states.

What you can do with it

If you maintain an open-source project that matters to infrastructure or user safety and your team can keep up with findings, you can opt in to OSS Scanner via GitHub — enrollment details are in Anthropic's announcement post. Maintainers doing security work can apply for a free Claude Max subscription, and for expanded defensive access through the Cyber Verification Program.

If your company builds security products or services for critical infrastructure, Anthropic has opened registration for joining the Defense Program. And even if you just consume open source: the same class of models attackers use is now scanning the shared code your software depends on — expect more disclosed vulnerabilities in your dependency tree, and keep your updates current.