The US Cybersecurity and Infrastructure Security Agency (CISA) has enlisted the powerful AI-driven tool Mythos from Anthropic to scan and audit federal government software for security vulnerabilities. This move is part of a proactive effort to identify and patch potential weaknesses that could be exploited by foreign intelligence agencies or cybercriminals.
According to sources familiar with the matter, CISA’s Attack Surface Evaluation team has been utilizing Mythos to scan code repositories across various federal agencies. While specific details about the number of software vulnerabilities uncovered, their severity, or the impacted agencies remain undisclosed, it is reported that a “large number” of flaws have already been discovered.
This AI-driven initiative is particularly noteworthy given the recent tensions between Anthropic and US government officials. Earlier this year, the company faced criticism for refusing to remove built-in safeguards restricting its models from being used for autonomous weaponry or domestic surveillance. In response, the Pentagon designated Anthropic as a supply-chain risk, typically reserved for foreign firms suspected of espionage.
It’s also worth noting that the National Security Agency (NSA) is believed to be using Mythos in its operations. This highlights the growing reliance on advanced AI tools by US intelligence and defense communities to stay ahead of emerging threats.
The use of Anthropic’s technology comes as the company continues to navigate regulatory battles surrounding its public-facing rollouts. When it launched its Fable model earlier this month, concerns from the White House regarding foreign nationals accessing the tool led to an abrupt administrative demand to restrict access. This led to a temporary global shutdown of the Fable model, which was only lifted last week.
While these developments may seem complex and technical, they underscore the critical importance of AI in cybersecurity efforts. As the threat landscape continues to evolve, it’s clear that advanced tools like Mythos will play an increasingly central role in identifying vulnerabilities and protecting sensitive systems.
For those concerned about their own organization’s security posture, this serves as a stark reminder of the need for proactive measures against emerging threats. With AI-powered scanning tools becoming more prevalent, it’s essential to stay informed about the latest developments in this space and consider how they can be integrated into your organization’s risk management strategy.
Source: SecurityWeek — 2026-07-07