What was announced. Two programs. The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers and Anthropic’s threat research to the providers that grid, water and transport operators already lean on. Founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic says it is starting with “a small cohort” and that several partners already use Claude to fix vulnerabilities. Pricing, and whether partners pay for model access: Undisclosed. Axios noted Anthropic didn’t say who covers the cost.
OSS Scanner is free and opt-in for open-source projects with “critical impact on infrastructure and user security,” on criteria modeled on Google’s OSS-Fuzz. Enrolled projects get periodic scans from Anthropic’s strongest models, including Claude Mythos. Each report carries a working proof of concept, an explanation and a suggested fix where one exists, and goes out without human review. Anthropic expects a true-positive rate above 90%. In its validation run, pentesters checked 97 critical and high findings across 48 projects: 85 cleared its disclosure bar, 11 were real but duplicates, one was a false positive.
The number that matters. Anthropic says its models found over 29,000 candidate vulnerabilities in six months. Humans have reviewed about 6,000. Nearly 5,000 unreviewed reports have already gone to maintainers who asked for everything. Finding bugs is no longer the hard part. Fixing them is. Anthropic says so itself: in Project Glasswing it often saw months pass between a bug being found and being fixed.
What it means for enterprises. Expect more patches, sooner, in the open-source code your software is built on. It lands as a steady rise in dependency updates and advisories, not one big event. What we’d do this quarter: know what you run (if you can’t list your open-source components in an SBOM, a software bill of materials, you can’t act on a surge of fixes); triage by reachability, because a flaw in a library you never call isn’t urgent; and ask every vendor how it takes in AI-found vulnerabilities and how fast they reach your console. If you run plants or utilities, ask your OT security provider whether it’s in the program and what changes on your sites. AI doesn’t fix the core OT problem: many systems can’t go offline to patch.
Tailwind for most pure plays. More disclosed bugs means more demand for the tools that sort, patch and watch: exposure management (Tenable, Rapid7), endpoint and runtime detection (CrowdStrike, SentinelOne), and network enforcement for systems that can’t be patched yet (Palo Alto Networks, Fortinet, Zscaler). Anthropic can find a bug. It doesn’t run your SOC, your endpoints or your firewalls. And it chose to work through CrowdStrike, Palo Alto, Dragos and Nozomi rather than around them.
Headwind for a narrow slice. Point code scanners (static analysis, dependency scanning) and the middle tier of manual pentest and bug bounty work now compete with free, frontier-grade scanning that attaches an exploit and a patch. That compresses price. Investors already flinched once: when Anthropic previewed Claude Code Security in February, JFrog fell about 25% and GitLab about 8% in a day, and Bank of America said code scanning was where the threat was real. Snyk and Wiz-style code features need to show what they add on top of the model. The long-run risk is that the lab becomes the platform. Today Anthropic sells through partners. It now also has engineers on site and its own threat research. Watch who owns the customer.
Our verdict. Near-term tailwind for most pure plays, real headwind for point code scanning. It also partly cuts against what we argued on X and LinkedIn on Oct 6: that labs should put independent security vendors in the release path to validate and sign off. Anthropic did bring vendors in, but as delivery partners, and it is shipping unreviewed scanner output straight to maintainers. Partnership, yes. Independent sign-off, not yet. Earlier this week Anthropic also folded Glasswing into its expanded Cyber Verification Program.
What to watch. Whether CIDP pricing or partner economics get disclosed. OSS Scanner’s real false-positive rate once maintainers report back at scale. Whether OpenAI (Codex Security, formerly Aardvark) and Google (Big Sleep, CodeMender) answer with programs of their own. Patch and CVE volume in enrolled projects. And code-security vendors’ next earnings calls, where pricing pressure shows up first.
Desk sheet: Anthropic Cyber Mission, launched Oct 8, 2026. CIDP: 11 founding partners, frontier Claude models, on-site engineers, threat research; pricing Undisclosed. OSS Scanner: free, opt-in, eligible critical OSS projects, model-generated reports with PoC and fix, no human review, expected true-positive rate above 90%. 29,000+ candidate vulns found in six months, ~6,000 human-reviewed. Dollar commitment: Undisclosed.
