Anthropic’s models have outrun the people who patch what the models find.
Its disclosure dashboard lists 29,439 findings discovered between November 1, 2025, and October 2, 2026. As of October 2, the company disclosed 6,157 findings across 591 open-source projects. The 6,157 findings were reported to their maintainers, while 516 were patched upstream, to Anthropic's knowledge. However, that “does not guarantee that those patches have been widely installed," the company said.
The Anthropic Cyber Mission the company announced Oct. 8 shifts more of the validating to providers and maintainers.
Outside firms reviewed 6,123 findings and confirmed that 5,674 were valid. Of the 6,157 reported, 1,333 came through that triage. The other 4,824 went “direct to maintainers,” which the dashboard says “may contain false positives.”
Track one is the Critical Infrastructure Defense Program. It sends frontier Claude models, on-site engineers, and Anthropic's threat research to 11 partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation, which Anthropic calls “a small cohort of providers.”
Anthropic says its June program for state, local, tribal, and territorial governments reached “more than half of all US states,” and “security teams of any size” can apply to its expanded Cyber Verification Program.

Track two, OSS Scanner, gives enrolled projects free periodic scans with a reproducer, an explanation, and a candidate patch when one exists. “The reports are model-generated and sent without human review,” the announcement says.
Terms unpublished, and fixes that run months or decades in rare cases
Anthropic didn’t specify whether partners will receive free model access or who will cover the computing costs, Axios reported. In Glasswing, Anthropic often saw months pass between a vulnerability being found and being fixed, the company says, and an OT fix “may have to wait” until it is safe to apply to running machinery, where “in some rare cases, this might take decades.”
“Critical infrastructure is hard to defend in many ways that AI cannot fix, but we believe that frontier models can help find and repair weaknesses before those weaknesses are used to cut off power or make water unsafe,” the announcement states.
The infrastructure track reaches operators through their providers
On July 30, the FBI and EPA warned that water and wastewater utilities in at least seven states had reported attacks on internet-facing Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers since July 27, with “loss of pressure and flooding” among the effects. Their first recommendation was “removing PLCs from direct internet exposure via secure gateway and firewalls.” Rockwell Automation is a founding partner of the new program, and the FBI notes other controller brands warrant the same considerations.

Tom Dobbins of the WaterISAC told CyberScoop that “OT systems that are exposed to the internet are a major challenge, and many of these systems that are older generation need to be not accessible to the internet.”
Cynthia Kaiser, formerly of the FBI and now at Halcyon, told Nextgov in May that “it’s not just about getting access,” and that the question is “where do they start?”
Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told VentureBeat in an exclusive interview in April, months before CrowdStrike joined the Critical Infrastructure Defense Program as a founding partner, that “the problem is patching.” At ten times today's findings, he said, “they’re going to be completely underwater.”

85 of 97 early scanner findings cleared the disclosure bar
Outside penetration testers checked 97 critical and high findings in 48 projects. Of those, 85 met the disclosure bar, 11 were real but duplicated known issues, and one was a false positive. Anthropic expects a true-positive rate above 90%. Some maintainers have said that “severity ratings can be inflated or the scanner misunderstood the project’s threat model.”
Todd Ouska of wolfSSL said that, “of the 74 reports we received, all but two were valid, and five became CVEs.” Maintainers enroll by pull request, and Anthropic says it will keep manual, human-reviewed disclosure for projects that need it.
A $100 million bill would authorize operators' frontier-model access
Rep. Josh Gottheimer’s AI Cyber Defense Act would authorize $100 million for a CISA pilot from 2027 to 2031, giving critical infrastructure operators free frontier-model access, if appropriators fund it. Meyers made the same point in April: Many “think tokens are free, but they’re not free.” Gottheimer said that “many of our local communities just don’t have the resources they need to pay for AI tokens to do the patching they need,” CyberScoop reported.
Five checks for security leaders
Check provider access. Ask your OT provider whether it is one of the 11 founding partners and what your organization actually receives. Anthropic hasn't published who pays for model access or computing costs.
Remove PLC internet exposure. Work with your OT team to take any PLC off direct internet exposure, as the FBI and EPA recommend. That exposure is a risk today, whatever happens with fix timing. Anthropic says it "often saw months pass" between finding and fix during Glasswing.
Track open-source dependencies. Check the OSS Scanner repository for projects you depend on, then watch their advisories and upstream releases. The reports go to maintainers, not to you.
Verify fixes are installed. Track separately when a patch is released and when it's installed on your systems. Where patching has to wait for a safe maintenance window, track the stopgap protections you rely on in the meantime. Anthropic's dashboard warns that upstream patches may not be widely installed.
Apply for model access directly. If your team does defensive work, apply to the Cyber Verification Program yourself. Your OT provider’s seat in the program is the provider’s, and it does not pass model access through to you. Anthropic says security teams of any size can apply, and it verifies applicants before granting access.
