Anthropic is about to send volunteer open-source maintainers vulnerability reports that nobody at the company has read. The service, OSS Scanner, is free, and Anthropic’s announcement on 8 October says its reports are “model-generated and sent without human review.” The post spells out the price: maintainers get findings faster, but “some will contain inaccuracies, such as a wrong severity rating.” Anthropic expects “a true-positive rate above 90%,” which means it expects as many as one report in ten to be wrong.
OSS Scanner is opt-in and modelled on Google’s OSS-Fuzz, the long-running service that hunts for bugs in open-source code. Enrolled projects are scanned on a regular schedule by Anthropic’s strongest models. A report arrives with a written explanation, a demonstration of how an attacker could use the flaw, and, when the model has one, a proposed patch. Anthropic says it built this because some maintainers, after Project Glasswing, asked for everything the models had found, reviewed or not. It limits the service to projects that can keep up with the volume. Everyone else still gets disclosures that a person has verified.
The second admission explains why the company is willing to ship unchecked output. Anthropic says the many vulnerabilities found by Glasswing partners have not yet translated into enough less cyber risk. Finding vulnerabilities is “easier than ever,” the post says, but “verifying, prioritizing, and fixing these findings remains challenging.” Months often passed between a bug being found and being fixed. Glasswing, the earlier effort that Anthropic folded into its expanded Cyber Verification Program this week, was the lesson behind both new programmes.
The other programme is the Critical Infrastructure Defense Program, and the problem it targets is older. Think of the machines that keep a factory, a rail line, a water utility or the electric grid running. Industrial networks, the software that steers them, and the controllers on the floor are designed to serve for decades. Engineers call this operational technology. Switching it off for an update is frequently impossible, so a flaw everyone knows about can stay open for years. Anthropic says the repair sometimes has to wait for a moment when running machinery can safely take it, which in rare cases could mean decades.
The program gives the security providers who look after that equipment threat research, engineers working on their premises, and access to Claude’s frontier models. Eleven founding partners are signed up, including CrowdStrike, Dragos, Palo Alto Networks, and Rockwell Automation, and Anthropic says some are already using Claude to fix vulnerabilities. It starts with a small cohort. Dan Gunter, chief executive of Insane Cyber, gives the clearest account of the constraint. The sites that most need protection are “remote substations, offshore platforms, and air-gapped plants,” he says, and “what no one had solved was the hours: more data than any team can work through, at more sites than any team can staff.”
Anthropic also says that since a June programme for state, local, and tribal governments, it has offered Claude models and support to more than half of US states. That count is the company’s own. On the open-source side it has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation, and backs Akrites and Gold Eagle, which pool vulnerability reports from many sources so maintainers are not swamped. A fund launched in August, the Defender Advantage Fund, keeps OSS Scanner free. The post gives no amounts for any of it.
The argument underneath all of this is one Anthropic only half acknowledges. The company sells the models that have made exploiting software cheap, and its answer to a flood of machine-found bugs is more machine-found bugs, now delivered without a reviewer. It does concede the timing. “Our forecast is that in two years, AI will favor defense,” it writes, then adds: “But in the near term, that may not be true.”
That leaves the near term to the maintainers. Anyone who enrolls a project is agreeing to do the verification Anthropic has chosen to skip, and the first wrong severity rating will be the test of whether free scans are worth the triage.
Anthropic, “Introducing the Anthropic Cyber Mission,” published 8 October 2026.