Back Gbhackers Anthropic Launches Cyber Mission to Protect Critical Infrastructure and Open
Anthropic launched its Cyber Mission, a long-term initiative aimed at helping defenders secure critical infrastructure and open-source software. This initiative utilizes frontier Claude models , offers engineering support, conducts threat research, and provides funding.
The Cyber Mission introduces two key components: the Critical Infrastructure Defense Program (CIDP) and the OSS Scanner, a free, opt-in service for discovering vulnerabilities.
These initiatives address a growing concern: while AI makes it easier to identify vulnerabilities, the processes of validating findings, coordinating disclosures, and deploying fixes remain resource-intensive.
The CIDP specifically targets operational technology that supports power grids, water utilities, factories, and transportation networks. These environments rely on industrial controllers, proprietary software, and equipment designed to function for decades.
Unlike conventional enterprise systems, industrial assets often cannot be taken offline for patching. Even small changes require careful validation, as an improper update can disrupt production or compromise essential services.
Anthropic plans to provide frontier Claude models, on-site engineers, and threat research through established infrastructure security providers and equipment manufacturers.
Founding partners for this initiative include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
Several of these partners are already using Claude to identify and repair vulnerabilities and assist clients with remediation. Anthropic will initially work with a selected group of partners to determine which approaches are suitable for live industrial environments.
The company also reported that its government cyber defense program has supplied models and technical support to more than half of U.S. states, aiding in code scanning, patching, incident response, and red teaming.
The OSS Scanner delivers periodic assessments using Anthropic’s most advanced models. Reports include an exploit reproducer, an explanation of the vulnerability, and a proposed patch when applicable. Findings are provided without human review, allowing for faster delivery but placing the onus for verification and prioritization on the maintainers.
Anthropic’s research highlights a validation bottleneck: its models identified over 29,000 candidate vulnerabilities in a six-month period, but only around 6,000 underwent manual review and triage. It is important to note that these figures represent candidate findings rather than confirmed vulnerabilities.
In an initial evaluation, penetration testers reviewed 97 critical and high-severity findings across 48 projects. Of these, eighty-five met Anthropic’s criteria for coordinated disclosure, eleven identified real but duplicate issues, and one was deemed invalid.
The company cautioned that severity ratings may be inflated or that threat models may be misunderstood.
For projects that lack the capacity to process automated reports, human-verified disclosures will continue to be provided through Anthropic’s existing coordinated vulnerability disclosure process.
The Cyber Mission builds upon Project Glasswing and the expanded Cyber Verification Program , shifting focus toward resolving findings rather than merely generating them.
Future work will involve automated triage, patching, secure architecture research, and software supply-chain protection. Anthropic recognizes that while AI can assist, it cannot eliminate operational constraints; the success of defensive measures ultimately depends on verified fixes, safe deployment, and collaboration with maintainers and infrastructure operators.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC .
Artificial Intelligence
Cyber security Course
Cyber Security Resources
Cybersecurity
Information Gathering
Information Security Risks
MATCHBOIL Malware Adds Sandbox Checks, .NET Reactor Obfuscation and Persistent C2
Critical Citrix NetScaler Vulnerability Allows Remote Code Execution Attacks – CVSS 9.5
Microsoft Pushes Enterprises to Test Post-Quantum Certificates Before Large-Scale Migration
Microsoft Teams to Introduce Deepfake Detection to Identify AI-Generated Audio and Video in Meetings
Critical Sungrow Authentication Bypass Flaw Lets Hackers Take Control of Solar Power Plants
FBI Warns Chinese Hackers Use Automated Tools and Botnets to Steal Sensitive Data
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
