Skip to content
TEN Brief Ten verified stories a day 2026.10.11 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 3 min read · Breaking

Anthropic Cyber Mission sends AI and engineers to power grids and water plants — open-source scans are free

Anthropic Cyber Mission, announced on October 8, 2026, has two parts. A critical-infrastructure defence programme gives operators of power grids, water systems, factories, transport networks and government systems Claude models, on-site Anthropic engineers and threat research. An OSS Scanner runs regular security scans of opt-in open-source projects with Anthropic's top model, for free, and can send reports without human review. Anthropic said six months of scanning produced more than 29,000 candidate vulnerabilities, of which only about 6,000 had been reviewed by people — the gap the programme is meant to close. Eleven founding partners range from security firms such as CrowdStrike and Dragos to consultancies and industrial suppliers

Two engineers seen from behind walking beside round settling tanks at a sunlit water plant

The three lines

  • Infrastructure — Claude plus on-site engineers for grid, water, factory and transport operators
  • Open source — free opt-in scans; reports can go out without human review
  • Numbers — 29,000+ candidate bugs in six months, only about 6,000 reviewed by humans

Key questions

What is Anthropic Cyber Mission
**A two-track defensive programme launched October 8, 2026.** | Track | Critical infrastructure defence | OSS Scanner | |---|---|---| | Who | Grid, water, factory, transport and government operators | Opt-in open-source projects | | What | Claude models + on-site engineers + threat research | Regular scans with Anthropic's top model | | Cost | Not disclosed | Free | | Human review | With partners and engineers | Optional — reports can go straight out |
Anthropic Cyber Mission partners
**Eleven founding partners in three groups.** | Group | Partners | |---|---| | Security firms | CrowdStrike, Palo Alto Networks, Dragos, Nozomi Networks, Insane Cyber | | Consultancies | Accenture, Deloitte, PwC, Booz Allen | | Industrial | Rockwell Automation, Hitachi |
Anthropic OSS scanner unreviewed reports
**AI finds bugs faster than humans can check them, so maintainers can choose raw reports.** | Item | Figure | |---|---| | Candidate vulnerabilities in six months | 29,000+ | | Reviewed by humans | about 6,000 (about 21%) | | Expected true-positive rate | 90%+ (Anthropic's estimate) | | Report contents | Description, proof of concept, fix where possible | | Severity ratings | May be wrong (Anthropic says so) |

A water plant's pumps cannot simply be switched off for a patch, so they run for years with known holes. Anthropic Cyber Mission, launched on October 8, 2026, is aimed at that problem. Anthropic will send Claude models and its own engineers to companies that run power grids, water systems, factories and transport networks, and it will scan open-source projects for vulnerabilities for free. The same week, CrowdStrike reported that a Chinese-speaking attacker had chained AI tools to break into South Korean banks ("CrowdStrike: Korean bank hacker used Claude Code and DeepSeek"). Anthropic's argument: if attackers are getting faster with AI, defenders need it too.

1. Two tracks — people for infrastructure, scans for open source

ItemCritical infrastructure defenceOSS Scanner
WhoOperators of grids, water, factories, transport, government systemsOpen-source projects that opt in
What they getClaude models + on-site engineers + threat researchRegular scans with Anthropic's top model
CostNot disclosedFree
First stepStart with a few operators to find safe ways of working in the fieldSign-up
Human reviewPartners and engineers involvedOptional — reports can go straight out

Anthropic said infrastructure defenders "have long faced severe staffing shortages" and that the gap has grown. AI now finds bugs quickly, but confirming, prioritising and patching still take time and skilled people, so Anthropic is sending engineers along with the model. Operational technology (OT) — the control systems behind physical equipment — is hard to patch because it often cannot be taken offline.

The 11 founding partners fall into three groups: security firms (CrowdStrike, Palo Alto Networks, Dragos, Nozomi Networks, Insane Cyber), consultancies (Accenture, Deloitte, PwC, Booz Allen) and industrial suppliers (Rockwell Automation, Hitachi). Anthropic said it has offered models and technical help to more than half of US state governments since June.

2. The numbers — 29,000 candidates, 6,000 reviewed

ItemFigure
Candidate vulnerabilities found in six months29,000+
Reviewed and triaged by humansabout 6,000 (about 21%)
Expected OSS Scanner true-positive rate90%+ (Anthropic's estimate)
Report contentsDescription + proof of concept + fix where possible
Severity ratingsCan be wrong (Anthropic says so)

This table is why the scanner exists. Human review cannot keep pace with AI discovery. Some maintainers asked to receive everything, reviewed or not. So Anthropic will send unreviewed reports to projects that want them, and keep sending human-checked reports to projects without the capacity to triage. Knowing which components sit inside which products — a software bill of materials — is what lets defenders prioritise such a flood ("What an SBOM is").

3. The trajectory — from vetted access to field deployment

StageAnthropic's cyber measures
Project GlasswingTop models opened to vetted organisations to hunt security problems
Earlier in October 2026Three-tier cyber verification programme — defence, authorised penetration testing, safety-critical testing
October 8, 2026Cyber Mission — infrastructure field deployment + free open-source scans
AlongsideDefender Advantage Fund — pilots and keeping the scanner free

Longer term, Anthropic says it wants to automate most triage and patching and to research new security architectures and coding standards. Its success measures are fewer exploitable weaknesses, more reliable essential services and faster recovery after attacks. Anthropic itself wrote that AI cannot solve every infrastructure security problem.

4. What remains and what is unconfirmed

  • Eligibility and cost: Who can join the infrastructure programme, on what terms and for what fee, was not disclosed.
  • Risk of unreviewed reports: Wrong reports could add to maintainers' workload. Who validates fixes before they reach infrastructure is another open question.
  • Competition: OpenAI runs its own programme offering defensive tools to companies and governments. Some see frontier labs using security work to earn a "social licence."
  • Outside the US: The announcement is US-focused; participation by operators elsewhere, including South Korea, was not mentioned.

Sources

  1. Axios — Exclusive: Anthropic's new plan to protect critical infrastructure
  2. CyberScoop — Anthropic rolls out program for 'long-term commitment' to secure critical infrastructure, open source software
  3. Cybersecurity News — Anthropic Cyber Mission to support defenders with tools, research, and resources
  4. StreetInsider — Anthropic launches cyber defense program for infrastructure and open-source

Verification

Published
Last modified
Cross-check
Checked against 4 independent sources.
Unverified
  • Eligibility, terms and pricing for the infrastructure programme were not disclosed.
  • The 90%+ true-positive rate for the OSS Scanner is Anthropic's own expectation, not an independent measurement.
  • Anthropic says it offered models and technical help to more than half of US state governments; how many actually adopted them was not disclosed.
  • Whether operators outside the US, including in South Korea, can join was not stated.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related