Anthropic Launches Cyber Mission With 11 Founding Partners logo

Anthropic Launches Cyber Mission With 11 Founding Partners

Anthropic launched a cyber-defense initiative with 11 founding partners to help protect power grids, water systems and open-source software using Claude models and on-site engineers.

ShareXLinkedInEmail

THE RUNDOWN

1

The founding partner list -- Dragos, Nozomi Networks, Rockwell Automation -- targets operational technology specifically, meaning power grids and water systems, not just conventional corporate IT security.

2

OSS Scanner generates proof-of-concept exploit code without human review before it reaches maintainers, which is also exactly the kind of output an attacker scraping the same reports could use.

3

Project Glasswing's own numbers -- 29,000 candidate vulnerabilities but only 6,000 manually reviewed -- show AI-sourced vulnerability discovery still bottlenecks on human verification, not detection volume.

4

Established vendors like CrowdStrike and Palo Alto Networks partnering rather than competing suggests the security industry currently sees LLM triage as additive, a stance that may not hold if detection speed keeps outpacing review capacity.

The VC Read

Value Add VC analysis

The VC Read: For any security vendor integrating with Anthropic's Cyber Mission, ask how proof-of-concept exploits are gated before disclosure -- "no human review" on exploit generation is the line in this launch that deserves more scrutiny than the partner-count headline.

Analysis

Anthropic launched its Cyber Mission on October 8, a program combining Claude models, on-site engineers and threat research to help protect critical infrastructure and open-source software, with 11 founding partners signed on: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation, according to Cybersecurity News.

Two Programs, One Target: Operational Technology

The Critical Infrastructure Defense Program delivers frontier Claude models and on-site engineers to providers that defend power grids, water systems, transportation networks and government systems -- the operational technology environments Dragos, Nozomi Networks and Rockwell Automation specialize in, rather than conventional IT security. OSS Scanner, the second program, is a free, opt-in service that runs Anthropic's strongest models against open-source code to find vulnerabilities, modeled explicitly on Google's OSS-Fuzz, which has helped maintainers fix more than 11,000 bugs since 2016. Anthropic's version uses LLM reasoning instead of fuzzing to find them.

“What to watch: whether any of the 11 founding partners report a Cyber Mission-sourced fix for a real-world critical infrastructure vulnerability within its first quarter.”

The Cyber Mission builds on Project Glasswing, Anthropic's earlier internal effort that surfaced more than 29,000 candidate vulnerabilities over six months, of which roughly 6,000 received manual review, with an expected true-positive rate above 90%.

The Risk the Launch Doesn't Mention

OSS Scanner's reports include proof-of-concept exploits generated without human review before they reach the maintainer. That's useful for a defender who wants to verify a bug is real, but it also means Anthropic is routinely generating usable exploit code at scale -- the same capability an attacker would want, now produced as a byproduct of a free service. Having CrowdStrike and Palo Alto Networks as partners rather than competitors suggests established security vendors see LLM-based triage as complementary to their own tooling for now, a bet that could look different if Anthropic's models start finding bugs faster than human-reviewed pipelines can keep up.

This follows Anthropic's rewritten usage policy banning election interference and model abuse earlier this month, part of a broader pattern of the company formalizing guardrails around Claude's most consequential use cases.

What to watch: whether any of the 11 founding partners report a Cyber Mission-sourced fix for a real-world critical infrastructure vulnerability within its first quarter.

ShareXLinkedInEmail

Key Sources

2 sources

THE WIRE in your inbox— Tech, startup & VC news with The VC Read, a few times a week. Free to subscribe, no spam.