Anthropic launches its Cyber Mission: 11 founding partners for critical infrastructure defense and free model-run vulnerability scans for open-source projects
Anthropic turns cyber defense into a long-term program, starting with critical infrastructure and open-source software, and open-source maintainers can sign up directly.
// Key points
- The Critical Infrastructure Defense Program (CIDP) covers the OT systems behind power grids, water and transport as well as government systems, giving trusted security providers frontier Claude models, on-site engineers and threat research; its 11 founding partners include Accenture, CrowdStrike, Dragos, Palo Alto Networks and Rockwell Automation.
- OSS Scanner, inspired by Google's OSS-Fuzz, gives opted-in open-source projects periodic free scans from Anthropic's most capable models, with a proof of concept, explanation and suggested fix in each report.
- Reports are model-generated and sent without human review; Anthropic expects a true-positive rate above 90% and warns of errors such as wrong severity ratings. Projects that can't keep up continue to receive human-verified disclosures.
- Anthropic is also funding the Python Software Foundation, the Apache Software Foundation, and Alpha-Omega and OpenSSF via the Linux Foundation; earlier this week Project Glasswing was merged into the expanded Cyber Verification Program.
Builder's takeIf you maintain a widely used open-source library, I'd sign up for OSS Scanner, but assign one person to triage the reports first: no human review and roughly 90% true positives means about one in ten may be noise. I'll start by looking at report quality on the upload and parsing libraries AI Cloud Drive depends on.
// Background · from #Anthropic
Full timeline →- Oct 9 Anthropic updates its Usage Policy, effective November 12: new rules for controlling physical hardware and region limits that follow ownership
- Oct 8 Anthropic releases Claude Haiku 5.5 at $0.10 per million input tokens under 100K, about 75% cheaper than Haiku 4.5 on average; Sonnet 5.5 cache reads cut in half
- Oct 7 Anthropic expands its Cyber Verification Program into three tiers of access to advanced cyber capabilities on Opus 5.5, Sonnet 5.5 and Mythos 5.1