On Oct 8 Anthropic launched the Cyber Mission: (1) free opt-in OSS Scanner for critical open-source projects using strongest models including Claude Mythos, with PoC/explanation/candidate patches and >90% expected true-positive rate, no human triage; (2) Critical Infrastructure Defense Program with 11 founding partners including CrowdStrike, Palo Alto, Dragos, and Rockwell. Project Glasswing has surfaced 29,000+ candidate vulns.
Key Takeaways
- ✓Two tracks: free opt-in OSS Scanner (model-only reports) + Critical Infrastructure Defense Program (OT/power/water/transport; 11 founding partners)
- ✓Glasswing legacy: 29,000+ candidate vulns, ~6,000 human-triaged; ~5,000 reports sent when maintainers asked for bulk
- ✓Quality bar: 88% of 97 critical/high samples met CVD bar; expected true-positive >90% (no human review; severity can be off)
- ✓Enroll: core maintainers PR into Anthropic’s enrollment repo; also Claude for OSS free Max + Cyber Verification Program
- ✓Framing: OSS-Fuzz analogue for LLM scanning; enterprise Claude Security remains separate (research post)
Key Decision Metrics at a Glance
Turn your technical choice into a development budget
Compare 40 dev plans & simulate token costs vs $20/mo subscriptions
Project Links & Resources
Direct AccessIn-Depth Technical Analysis
Background
Attackers can find and exploit vulns with frontier models in minutes; OSS maintainers and OT defenders remain understaffed. Project Glasswing surfaced 29,000+ candidate vulns but humans triaged only ~6,000. On Oct 8 Anthropic launched the Cyber Mission: free opt-in OSS Scanner plus a Critical Infrastructure Defense Program.
Mechanism
OSS Scanner is an OSS-Fuzz analogue: enrolled projects get periodic free scans from strongest models (incl. Claude Mythos). Reports include PoC, explanation, and candidate patches without human review (expected >90% true positives; severity/threat-model errors possible). Human CVD remains for projects that need it.
CIDP brings Claude + on-site engineers + threat research to OT providers; 11 founding partners include CrowdStrike, Palo Alto Networks, Dragos, Rockwell, Accenture, Deloitte, and others. Glasswing folded into an expanded Cyber Verification Program.
Evidence
Anthropic cites CyberGym LLM find-rates rising from <20% to >85%, and an internal check where 88% of 97 critical/high scanner findings met CVD bar. Maintainer quotes (PostgreSQL, OpenSSL, wolfSSL, HotCRP) report high signal. These are self-reported / partner testimonials—not an independent leaderboard.
For developers
Core maintainers of critical OSS enroll via PR to Anthropic’s template repo. Also: Claude for OSS free Max, Cyber Verification Program, and enterprise Claude Security as a separate product. Build your own triage/repro pipeline before treating unreviewed model reports as CVE tickets.
Benchmark side-by-side against alternatives, or calculate monthly token cost vs subscription break-even.
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.