Analysis
Anthropic launched its Cyber Mission on October 8, a program combining Claude models, on-site engineers and threat research to help protect critical infrastructure and open-source software, with 11 founding partners signed on: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation, according to Cybersecurity News.
Two Programs, One Target: Operational Technology
The Critical Infrastructure Defense Program delivers frontier Claude models and on-site engineers to providers that defend power grids, water systems, transportation networks and government systems -- the operational technology environments Dragos, Nozomi Networks and Rockwell Automation specialize in, rather than conventional IT security. OSS Scanner, the second program, is a free, opt-in service that runs Anthropic's strongest models against open-source code to find vulnerabilities, modeled explicitly on Google's OSS-Fuzz, which has helped maintainers fix more than 11,000 bugs since 2016. Anthropic's version uses LLM reasoning instead of fuzzing to find them.
“What to watch: whether any of the 11 founding partners report a Cyber Mission-sourced fix for a real-world critical infrastructure vulnerability within its first quarter.”
The Cyber Mission builds on Project Glasswing, Anthropic's earlier internal effort that surfaced more than 29,000 candidate vulnerabilities over six months, of which roughly 6,000 received manual review, with an expected true-positive rate above 90%.
The Risk the Launch Doesn't Mention
OSS Scanner's reports include proof-of-concept exploits generated without human review before they reach the maintainer. That's useful for a defender who wants to verify a bug is real, but it also means Anthropic is routinely generating usable exploit code at scale -- the same capability an attacker would want, now produced as a byproduct of a free service. Having CrowdStrike and Palo Alto Networks as partners rather than competitors suggests established security vendors see LLM-based triage as complementary to their own tooling for now, a bet that could look different if Anthropic's models start finding bugs faster than human-reviewed pipelines can keep up.
This follows Anthropic's rewritten usage policy banning election interference and model abuse earlier this month, part of a broader pattern of the company formalizing guardrails around Claude's most consequential use cases.
What to watch: whether any of the 11 founding partners report a Cyber Mission-sourced fix for a real-world critical infrastructure vulnerability within its first quarter.