2026-10-08 · ← News
Anthropic offers free open-source scanning while maintainers inherit the verification bill
Anthropic launched its Cyber Mission with two tracks: critical-infrastructure defense through 11 partners and a free OSS Scanner. The scanner sends unreviewed model findings directly to maintainers, making verification and safe deployment of fixes the real bottleneck.
The image could not be loaded.
Anthropic has launched Cyber Mission, a long-term program for defending critical infrastructure and open-source software. One track connects Claude, company engineers and threat research with 11 founding partners. The other offers selected open-source projects recurring scans at no charge.
One program enters power plants while the other enters repositories
The Critical Infrastructure Defense Program starts with providers that protect operational technology in energy, water and transportation. Its 11 partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic promises access to its strongest Claude models, on-site engineers and threat research.
OSS Scanner is a free opt-in service for important open-source projects. Maintainers apply through a pull request and Anthropic verifies their role. The service is designed to scan projects repeatedly and deliver a proof of concept, an explanation and a proposed fix when the model can produce one.
Faster bug discovery transfers work to maintainers
Anthropic says it reviewed more than 6,000 reports in its earlier program. The new Scanner creates a faster route: outputs receive no human review or triage before delivery. The company expects a true-positive rate above 90%, while warning that severity ratings and reports can be wrong. That figure is a vendor expectation, not an independently measured production result for the new service.
Maintainers therefore receive a different kind of queue. Someone must reproduce each finding, remove duplicates, place it in the project's threat model, review the patch and release a version without regressions. Free scanning lowers the cost of discovering a candidate. It does not remove the cost of deciding whether the bug is real and whether the fix is safe to ship.
Critical infrastructure cannot patch by trying and hoping
Finding a vulnerability and generating a patch are insufficient for a power grid or water system. An operator must validate the effect on a specific control system, schedule operational changes and keep a human accountable. Anthropic has not published the infrastructure program's commercial terms or metrics that would demonstrate reduced risk in live environments.
The free OSS Scanner is also limited to projects that opt in and meet selection criteria. It is not a blanket service for every repository. A small team without a security owner may receive more useful leads than it can safely process.
Shipped fixes will measure value better than finding counts
The useful measures will be accepted unique findings, verification time, the share of usable patches and the number of fixes actually released to users. In critical infrastructure, the ability to test a change in a representative environment without disrupting operations will matter more than the number of vulnerabilities a model flags.
Anthropic is creating a practical test of its claim that AI can give defenders an advantage. If only report production gets faster while triage and deployment remain slow, Scanner will give security teams another inbox rather than a shorter risk list.
Lilith's verdict
Anthropic gives maintainers a free repository X-ray, but the image arrives without a radiologist. Value begins with fixes that survive human review and safely reach users.
I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.
Original source ↗ ↗