Anthropic Introduces Cybersecurity Initiative for Critical Infrastructure Protection
Anthropic PBC has officially launched a new initiative aimed at enhancing the cybersecurity of critical infrastructure, including power grids and water systems. This program, dubbed the Anthropic Cyber Mission, connects the company’s advanced models and onsite engineers with security firms focused on safeguarding vital infrastructure components.
As part of this initiative, Anthropic has unveiled the OSS Scanner, a service that provides free periodic vulnerability scans for open-source projects using its leading models. Both offerings are components of the Anthropic Cyber Mission, which reinforces the company’s commitment to bolstering defenses against cyber threats.
The Critical Infrastructure Defense Program focuses on outside providers that operators of various sizes have come to rely on for security advice, particularly concerning the implementation of updates and fixes. Eleven organizations have joined as founding partners, including major consulting firms like Accenture plc, Booz Allen Hamilton Inc., Deloitte & Touche LLP, and PricewaterhouseCoopers LLP. Notable security vendors such as CrowdStrike Holdings Inc. and Palo Alto Networks Inc. are also part of the initiative, alongside industrial specialists like Dragos Inc., Insane Cyber Inc., and Nozomi Networks Inc.
This program is particularly relevant for operational technology within facilities such as plants and substations, where aging equipment is often resistant to downtime for maintenance or patching. Vulnerabilities can persist for years without corrective action. Anthropic has indicated that several partners are already leveraging its model, known as Claude, to identify and rectify vulnerabilities. The organization plans to expand its partnerships and sectors in the coming months.
Andrew Turner, president of commercial cyber at Booz Allen, described operational technology as “the next frontier for autonomous AI-enabled attacks,” emphasizing the significant control that artificial intelligence could gain over industrial processes and the need for rapid responses to evolving threats.
Though the announcement did not clarify the commercial terms of partnerships, Axios reported that details regarding model access and computing cost responsibilities remain undisclosed. The implications of how partners will test and implement security fixes without affecting utility operations were also questioned in the report.
The OSS Scanner initiative emerged from Anthropic’s backlog of vulnerability disclosures. Over the past six months, the company’s models have identified more than 29,000 candidate vulnerabilities in widely utilized software, with staff manually reviewing around 6,000 cases. As a response to increasing demand, nearly 5,000 early disclosure reports have since been issued to maintainers who requested access to the unreviewed data.
This scanner takes inspiration from Google’s OSS-Fuzz, which actively employs fuzzing techniques to identify weaknesses in open-source code. Each vulnerability report generated by the scanner includes a self-contained reproducer to streamline the remedial process. Early tester Anton Arapov from the OpenSSL Corporation remarked that reports containing viable exploits effectively complete much of the engineering work.
The reports generated by the OSS Scanner are distributed directly to maintainers without manual review, which could result in mistakes, such as incorrect severity ratings. To assess the accuracy of the scanner prior to its broader rollout, Anthropic evaluated 97 critical and high-severity findings across three dozen projects, successfully clearing 85 for disclosure. Notably, the embedded encryption library wolfSSL Inc. confirmed that all but two of the 74 reports it received during initial trials were valid, with five leading to official CVE designations.
Eligible open-source maintainers can enroll in the OSS Scanner service by submitting a pull request on an Anthropic GitHub repository. Admissibility follows the OSS-Fuzz criteria based on “critical impact on infrastructure and user security,” with evaluations conducted on a case-by-case basis. For projects lacking sufficient resources to manage raw findings, Anthropic will provide human-verified reports through its existing disclosure process.
The funding for keeping the scanner service free comes from the Defender Advantage Fund established by Anthropic in August. The company has also made commitments to support organizations such as the Python Software Foundation and the Apache Software Foundation, along with Alpha-Omega and OpenSSF through the Linux Foundation.
Both the Cyber Mission and OSS Scanner draw upon insights gained from Project Glasswing, which offered access to its Claude Mythos model until it was integrated into an expanded Cyber Verification Program earlier this week. Anthropic asserts that identifying vulnerabilities has become increasingly accessible; however, the challenges of verifying, prioritizing, and remediating these issues remain, and the company acknowledges that while improvements have occurred, overall cyber risk reduction is still insufficient. Moreover, in the context of operational technology, fixes often depend on the availability of safe downtime, which can be a lengthy process, potentially spanning decades.

