Updates·October 9, 2026, 00:42
Anthropic launches free security scanner for open source
AI-generated and checked against the sources listed below.
Anthropic has launched a program for protecting critical infrastructure and a free scanner, OSS Scanner, that looks for security holes in open source projects.

What's new
Anthropic, the company behind the AI assistant Claude, has unveiled two new security initiatives under the heading Anthropic Cyber Mission. The first is called the Critical Infrastructure Defense Program (CIDP). It makes Claude's most powerful models, on-site engineers and threat research available to those who protect power, water, transportation and public infrastructure. The program has 11 founding partners, including Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Work is already underway at several of them.
The second is OSS Scanner, a free service for open source projects. Open source is software whose code is open to everyone and which is used in almost all modern IT.
What's clever
OSS Scanner periodically runs Anthropic's most powerful models over a project's code and looks for security holes. Each report contains proof that the flaw can be exploited, an explanation and a suggested fix. The reports are written by AI without human review. That makes them faster than the normal process, but there may be errors. Anthropic expects more than 90 percent of the findings to be correct. In a test with external experts, 88 percent of 97 serious findings met Anthropic's requirements, and only one of the remaining 12 was a false alarm.
Projects sign up themselves. Core maintainers can be enrolled via a template in a GitHub repository. Projects that cannot handle many findings instead get findings that humans have checked.
The cost is kept down by a special fund, the Defender Advantage Fund. Anthropic has also given money to the Python Software Foundation, OpenSSF and the Apache Software Foundation, among others.
Cheaper or better?
OSS Scanner is free for the projects that are accepted. However, they must be projects of great importance to infrastructure and user security, and Anthropic assesses each case individually. The price of CIDP has not been disclosed. Companies that build security products for critical infrastructure can simply register interest via a form.
For comparison, Google has long had OSS-Fuzz, which is used as a model for the criteria. Direct tests against competitors' tools have not been disclosed. According to Anthropic, its earlier work with Project Glasswing and the model Mythos Preview went through more than 1,000 open source projects and found an estimated 6,202 serious vulnerabilities. Open questions include whether the offer applies in Denmark and the EU. That is not clear from the sources, but open source projects are international.
What it's good for
OSS Scanner is good for maintainers of widely used open source libraries who cannot afford expensive security audits. Flaws in such programs eventually also hit ordinary businesses and citizens.
CIDP is aimed at security firms and suppliers that protect power plants, water supply and transportation. For an ordinary user, the point is indirect: if the holes are found and patched faster, the services we all use become safer. Maintainers can also get free Max subscriptions to Claude via Claude for Open Source.
Sources
Get the week's AI news in your inbox
Choose your level, topics and length. One email a week, unsubscribe at any time.
Subscribe to Promptly Newsletter



