Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
Anthropic Launches Cyber Mission: Free Unreviewed AI Bug Scans for Open Source, Claude Access for 11 Infrastructure Security Firms

Anthropic launched the Anthropic Cyber Mission today, Oct. 8, calling it "a long-term commitment to securing the systems everyone depends on." It starts with two programs: one for the industrial systems behind power grids and water utilities, one for open-source code.
The company's stated reason is blunt. "Highly cyber-capable AI models are widely available to attackers now," Anthropic wrote, while defensive tools "have not yet reached enough of the defenders who need them." It also says state-sponsored adversaries "have spent years gaining footholds" in these systems so they can disrupt them. It did not name any country.
Critical infrastructure: eleven providers get Claude and engineers
The Critical Infrastructure Defense Program supplies frontier Claude models, on-site Anthropic engineers and the company's threat research to the providers that operators of critical systems already rely on. Anthropic is not selling to utilities directly.
The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic describes them as consultancies that run security programs, security firms that guard industrial networks, and manufacturers that build and patch the equipment.
The target is operational technology: controllers, control software and industrial networks built to last decades. Anthropic says these systems "often cannot be taken offline to patch, so known vulnerabilities can stay unresolved for years."
"This work is underway," the company says, with several partners already using Claude to fix vulnerabilities. It calls this a first step with "a small cohort of providers." Other firms that build security products for critical infrastructure can register interest through a form.
CrowdStrike said "critical infrastructure facing machine-speed threats requires machine-speed defense." Palo Alto Networks said it is pairing its Unit 42 threat intelligence with Anthropic's models. Booz Allen called operational technology the next frontier for autonomous AI-enabled attacks.
This builds on an earlier program. Anthropic says its June effort for state and local governments, reported by StateScoop as a $15 million commitment, has offered Claude models and support to more than half of U.S. states.
OSS Scanner: faster reports, no human check
The second program is OSS Scanner, a free opt-in service. Enrolled open-source projects get periodic scans from Anthropic's strongest models, including Claude Mythos. Each report includes a proof of concept showing how the bug could be exploited, an explanation, and a suggested fix where one exists.
The catch is stated in Anthropic's own announcement. The reports "are model-generated and sent without human review," and "some will contain inaccuracies, such as a wrong severity rating." Anthropic says that is the price of speed.
Anthropic says it expects a true-positive rate above 90%. That is a projection, not a measured result. Early validation figures point close to it: 85 of 97 flagged vulnerabilities, about 88%, met formal disclosure standards, though those findings came out of a much larger pool of more than 29,000 candidates surfaced during Project Glasswing, of which roughly 6,000 were human-reviewed.
The service is meant for projects that already keep up with verified high and critical reports. Everyone else keeps receiving human-verified disclosures. Anthropic says the model is "inspired by Google's OSS-Fuzz" and that some maintainers asked for everything the models found, reviewed or not.
The maintainer-burden problem
There is a live tension here. The Verge reports that some open-source projects, including Linus Torvalds' Linux kernel and Google, are already struggling with a flood of AI-generated bug reports. A tool that sends more model-written reports with no human triage lands in that environment.
Anthropic's answer is that the service is opt-in and limited to maintainers who can handle the volume. It also says it funds groups that collect and coordinate vulnerability reports so maintainers are not overwhelmed. Those include Akrites and Gold Eagle.
AI-assisted discovery has already produced real results. The "Copy Fail" flaw, disclosed in May, affected nearly every Linux distribution.
Money and the company's own admission
Anthropic says it has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. Crypto Briefing reports the company committed $100 million in usage credits through Project Glasswing and donated $4 million to organizations including OpenSSF and Apache. Anthropic's announcement as relayed does not break out those figures.
Project Glasswing began in April 2026. Earlier this week Anthropic folded it into an expanded Cyber Verification Program, which controls who gets access to Claude's full cyber capabilities. The Cyber Mission decides where Anthropic sends its own engineers, models and money.
Anthropic concedes Glasswing has not solved the problem. Partners uncovered many vulnerabilities, the company says, "but we haven't yet achieved a sufficient reduction in cyber risk." Finding bugs is easier than ever. Verifying, prioritizing and fixing them is not.
Its forecast cuts both ways. "In two years, AI will favor defense," Anthropic says. In the near term it warns the opposite may hold, because exploiting a vulnerability has become cheap while fixing one is slow and still depends on people.
It is unclear whether maintainers, many of them volunteers, can absorb unreviewed reports faster than attackers can use the same models to find the same flaws. Core maintainers can enroll their projects now through Anthropic's OSS Scanner page.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.