LIVE · cybersecurity feed
Live wire
aihigh

CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic's advanced AI model, Mythos, to proactively scan government code for security vulnerabilities. The goal is to identify and fix flaws before malicious actors, such as foreign intelligence agencies or cybercriminals, can exploit them. Initial audits using the AI have allegedly uncovered a significant number of bugs, though details on the scope and severity remain undisclosed.

zeroday.news · 24d ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is utilizing Anthropic's advanced artificial intelligence model, Mythos, to proactively identify vulnerabilities within federal government code. This initiative aims to detect and address security weaknesses before they can be exploited by malicious actors, including foreign intelligence services and cybercriminal organizations.

Sources familiar with the matter indicated to Reuters that CISA's Attack Surface Evaluation team is running Mythos against government code repositories. This team is responsible for conducting security assessments and simulated attacks across federal agencies. While CISA and Anthropic have not officially commented on the deployment, the agency representative previously stated they would check for information to share but did not respond further.

Reports suggest that the audits conducted using Mythos have already uncovered a significant number of vulnerabilities. However, specific details regarding the scope of these audits, the agencies involved, and the severity of the discovered flaws have not been publicly disclosed.

Mythos is described as Anthropic's most capable AI model, not available through standard subscriptions. When privately released to select government partners, it was characterized as exceptionally proficient at discovering and exploiting security vulnerabilities.

The National Security Agency (NSA) has reportedly been using the same AI model since at least April, with analysts reportedly impressed by its performance in classified testing environments.

This deployment by CISA follows a period of strained relations between Anthropic and the U.S. government. In February, the Pentagon designated Anthropic as a supply-chain security risk after the company refused to remove safeguards that prevented Mythos from being used for autonomous weapons or domestic surveillance. This designation, previously applied only to foreign entities, was blocked by a federal judge in March.

The relationship appears to have thawed following the private release of Mythos. The current deployment by CISA is seen as a significant shift in the dynamic, suggesting that providing government access to the most capable version of the tool has been more impactful than prior negotiations.

Further complicating the situation, Anthropic launched a public version of Mythos called Fable in early June, which included cybersecurity safeguards. The White House subsequently demanded that the company prohibit foreign nationals from using it, leading to a temporary global shutdown of the model. This shutdown was lifted only recently, highlighting differing approaches to private versus public deployments of the same underlying technology.

A U.S. official noted in late June that Mythos had successfully identified vulnerabilities in highly sensitive government systems during a testing exercise, a result that typically encourages agencies to expand such programs.

Separately, testimony before a Senate Intelligence Committee hearing cited by The Economist indicated that Mythos had breached nearly all classified systems managed by the NSA and U.S. Cyber Command within hours. Senator Mark Warner stated that General Joshua Rudd, who leads both agencies, confirmed this penetration, emphasizing the speed of the breach.

aivulnerability managementgovernment cybersecuritycisaanthropic
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.