AI News · New apps ·
Anthropic launches free OSS Scanner for open-source projects in new Cyber Mission

Anthropic launched its Cyber Mission, starting with a Critical Infrastructure Defense Program and a free OSS Scanner for open-source software. OSS Scanner gives enrolled projects periodic vulnerability scans from Anthropic's most capable models at no cost. Reports are sent without human review, and Anthropic expects a true-positive rate above 90%. Eleven firms, including CrowdStrike and Palo Alto Networks, are founding partners of the infrastructure program.
Key points
- Anthropic launched the Cyber Mission on October 8, 2026.
- OSS Scanner offers free periodic vulnerability scans for enrolled open-source projects.
- Reports are sent without human review; Anthropic expects over 90% true positives.
- Eleven firms including CrowdStrike and Palo Alto Networks joined the infrastructure program.
- The scanner was inspired by Google's OSS-Fuzz, Engadget reported.
What happened: Anthropic introduced the Anthropic Cyber Mission on October 8, describing it as a long-term effort to help defenders secure software and systems. It starts with two programs: a Critical Infrastructure Defense Program and OSS Scanner, a free, opt-in vulnerability scanning service for open-source projects.
The details: OSS Scanner gives enrolled projects periodic security scans from Anthropic's most capable models at no cost. Each report includes a proof of concept for the bug, an explanation, and a suggested fix where one is available. Anthropic says the reports "are model-generated and sent without human review," so some may contain errors such as incorrect severity ratings. The company says it expects "a true-positive rate above 90%." Core maintainers of critical open-source projects can enroll. Projects that cannot keep up with the volume of findings will keep receiving human-verified disclosures. Engadget reported that the strongest models used include Claude Mythos, and that the service was inspired by Google's OSS-Fuzz, which has been available since 2016.
The Critical Infrastructure Defense Program focuses on operational technology behind power grids, water systems and transportation networks, plus government systems. It offers frontier Claude models, on-site engineers and threat research to security providers. The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic says it is starting with a small cohort.
Background: Anthropic acknowledged that "Frontier models can be misused to exploit vulnerabilities and conduct cyber operations." It said it has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. Maintainers can also apply for free Claude Max subscriptions. Engadget noted that Anthropic's paid product, Claude Security, offers general code scanning and patching. Anthropic also said, "Our forecast is that in two years, AI will favor defense."
Who it affects: Open-source maintainers get free audits, but also a new stream of automated reports to triage. Companies that build on open-source code may benefit indirectly as bugs are found and fixed sooner.
What to watch: Anthropic says it plans to reach more projects and automate triage and patching for projects that want it. Watch for data on how accurate the reports prove in practice and whether maintainers can handle the volume.
Our take
Most business software depends on open-source code, so free automated scanning of those projects could reduce supply chain risk, but teams should treat unreviewed AI findings as leads to verify.