{"id":98743,"date":"2026-07-08T08:40:13","date_gmt":"2026-07-08T08:40:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/98743\/"},"modified":"2026-07-08T08:40:13","modified_gmt":"2026-07-08T08:40:13","slug":"cisa-deploys-anthropics-mythos-ai-to-hunt-vulnerabilities-in-u-s-government-code","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/98743\/","title":{"rendered":"CISA Deploys Anthropic\u2019s Mythos AI to Hunt Vulnerabilities in U.S. Government Code"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tCISA Deploys Anthropic\u2019s Mythos AI to Hunt Vulnerabilities in U.S. Government Code\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> July 08, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Anthropic-Claude-Code-Security.png\" alt=\"\"\/><\/p>\n<p>CISA is using Anthropic\u2019s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services.<\/p>\n<p class=\"wp-block-paragraph\">Three sources familiar with the matter told Reuters that CISA, the U.S. government\u2019s civilian cyber defense agency, is running Anthropic\u2019s <a href=\"https:\/\/securityaffairs.com\/tag\/claude-mythos\" type=\"post_tag\" id=\"16757\" rel=\"nofollow noopener\" target=\"_blank\">Mythos<\/a> AI model against federal code repositories to find vulnerabilities before foreign intelligence services and criminal groups do. <\/p>\n<p class=\"wp-block-paragraph\">Neither CISA nor Anthropic commented on the record. A CISA representative said last month he\u2019d check whether there was anything to share, then stopped responding.<\/p>\n<p class=\"wp-block-paragraph\">The operation is run by CISA\u2019s Attack Surface Evaluation team, a unit that conducts security assessments and simulated attacks across the federal government. Two of Reuters\u2019 sources said the audits have already turned up a large number of vulnerabilities. The exact scope, which agencies were covered, and how serious the bugs are have not been disclosed.<\/p>\n<p class=\"wp-block-paragraph\">Mythos is Anthropic\u2019s most capable model and it isn\u2019t something you can access through a standard subscription. It was described, when Anthropic privately released it to select government partners, as exceptionally capable at finding and exploiting security vulnerabilities. As Reuters reported: <\/p>\n<p class=\"wp-block-paragraph\">\u201cThe Cybersecurity and Infrastructure Security Agency is using Mythos to scan \u200bgovernment code repositories for bugs that could leave the door open for foreign spies and cybercriminals, \u200bthe sources said.\u201d <a href=\"https:\/\/www.reuters.com\/world\/us-cyber-agency-is-using-anthropics-mythos-audit-government-code-sources-say-2026-07-06\/\" rel=\"nofollow noopener\" target=\"_blank\">states Reuters<\/a>. <\/p>\n<p class=\"wp-block-paragraph\">The NSA has been using the same model since at least April, according to Axios, and NSA analysts testing it in classified settings came away impressed.<\/p>\n<p class=\"wp-block-paragraph\">The company\u2019s relationship with the U.S. government turned hostile in February when Anthropic refused to remove safeguards that prevented Mythos from being used for autonomous weapons or domestic surveillance. <\/p>\n<p class=\"wp-block-paragraph\">The Pentagon responded by designating Anthropic as a <a href=\"https:\/\/www.reuters.com\/world\/us\/trump-says-he-is-directing-federal-agencies-cease-use-anthropic-technology-2026-02-27\/\" rel=\"nofollow noopener\" target=\"_blank\">supply-chain security risk<\/a>, a label that had previously been applied only to foreign companies suspected of facilitating espionage. It was an extraordinary move against a domestic company, and it reflected how seriously the administration took Anthropic\u2019s refusal.<\/p>\n<p class=\"wp-block-paragraph\">A federal judge blocked the blacklisting in March. Relations began thawing after that, and the CISA deployment is a sign of how much the dynamic has shifted. <\/p>\n<p class=\"wp-block-paragraph\">\u201cThe \u200bextraordinary blacklisting was\u00a0<a href=\"https:\/\/www.reuters.com\/world\/us-judge-blocks-pentagons-anthropic-blacklisting-now-2026-03-26\/\" rel=\"nofollow noopener\" target=\"_blank\">blocked by \u200ba judge in March<\/a>, and\u00a0<a href=\"https:\/\/www.reuters.com\/legal\/government\/trump-says-anthropic-is-shaping-up-open-deal-with-pentagon-2026-04-21\/\" rel=\"nofollow noopener\" target=\"_blank\">the \u2060conflict has eased<\/a>\u00a0following the private release of Anthropic\u2019s Mythos, an AI model described as extremely capable at finding and exploiting cybersecurity vulnerabilities.\u201d continues Reuters.<\/p>\n<p class=\"wp-block-paragraph\">Giving the government access to the most capable version of the tool appears to have done more to repair the relationship than any amount of negotiation.<\/p>\n<p class=\"wp-block-paragraph\">When Anthropic launched <a href=\"https:\/\/securityaffairs.com\/tag\/fable-5\" type=\"post_tag\" id=\"16990\" rel=\"nofollow noopener\" target=\"_blank\">Fable<\/a> in early June, described as a public version of Mythos with cybersecurity safeguards added, the White House responded by demanding that the company ban foreign nationals from running it. That demand led to a temporary global shutdown of the model. It was lifted only last week, after what Reuters described as a standoff that illustrated how differently the administration treats the private and public deployments of the same underlying technology.<\/p>\n<p class=\"wp-block-paragraph\">The pattern is now clear: Mythos in government hands, scanning classified systems and federal code, gets quiet approval and active deployment. Mythos in public hands, accessible to anyone including foreign users, immediately triggers national security concerns and regulatory pressure. As Reuters noted on the timeline of events: <\/p>\n<p class=\"wp-block-paragraph\">\u201cwhen Anthropic rolled out a public version of Mythos called\u00a0<a href=\"https:\/\/www.reuters.com\/technology\/anthropic-rolls-out-public-version-mythos-without-cybersecurity-capability-2026-06-09\/\" rel=\"nofollow noopener\" target=\"_blank\">Fable<\/a>, \u2060which included \u200bwhat it described as cybersecurity safeguards, the White House suddenly demanded \u200bthat it ban foreigners from running it. This\u00a0<a href=\"https:\/\/www.reuters.com\/technology\/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13\/\" rel=\"nofollow noopener\" target=\"_blank\">triggered a global shutdown of the model<\/a>\u00a0that was\u00a0<a href=\"https:\/\/www.reuters.com\/business\/us-lift-export-controls-anthropics-fable-ai-model-tuesday-source-says-2026-06-30\/\" rel=\"nofollow noopener\" target=\"_blank\">lifted only last week<\/a>.\u201d continues the agency.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic has confidentially filed for a U.S. IPO. Having CISA, the NSA, and potentially other agencies actively deploying your most capable model is a materially different position than being on a Pentagon blacklist, and the company got from one to the other in under five months. <\/p>\n<p class=\"wp-block-paragraph\">A late-June AP report added another data point: a U.S. official said Mythos had identified vulnerabilities in highly sensitive government systems during a testing exercise, which is exactly the kind of result that makes agencies want to expand the program rather than wind it down. <\/p>\n<p class=\"wp-block-paragraph\">Senate testimony <a href=\"https:\/\/securityaffairs.com\/194016\/ai\/anthropics-mythos-ai-broke-into-almost-all-nsa-classified-systems-in-hours.html\" rel=\"nofollow noopener\" target=\"_blank\">claimed<\/a> Anthropic\u2019s Mythos AI breached NSA and Cyber Command systems in hours, prompting a U.S.-ordered shutdown.<\/p>\n<p class=\"wp-block-paragraph\">According to a\u00a0<a href=\"https:\/\/www.economist.com\/briefing\/2026\/06\/14\/donald-trumps-blocking-of-anthropic-is-capricious-and-chaotic\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a>\u00a0by The Economist citing a Senate Intelligence Committee hearing, Anthropic\u2019s Mythos model had penetrated nearly all classified systems managed by the NSA and US Cyber Command. Senator Mark Warner stated on June 11 that General Joshua Rudd, who leads both agencies, told him directly that Mythos had done it, and not in weeks.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEncryption was a potent technology, but narrow in its application. AI is far more powerful and versatile. On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon\u2019s Cyber Command, had told him that\u00a0Mythos \u201cbroke into almost all of our classified systems, not in weeks, but in hours\u201d.\u201dreported The Economist.<\/p>\n<p class=\"wp-block-paragraph\">The number of vulnerabilities found so far hasn\u2019t been disclosed, but two sources described it as large.<\/p>\n<p class=\"wp-block-paragraph\">Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p class=\"wp-block-paragraph\">(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0Mythos)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"CISA Deploys Anthropic\u2019s Mythos AI to Hunt Vulnerabilities in U.S. Government Code Pierluigi Paganini July 08, 2026 CISA&hellip;\n","protected":false},"author":2,"featured_media":72866,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,6455,2213,315,8066,7512,8067,8068,8069,8070],"class_list":["post-98743","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-anthropic","tag-cisa","tag-claude-mythos","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-pierluigi-paganini","tag-security-affairs","tag-security-news"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/98743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=98743"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/98743\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/72866"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=98743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=98743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=98743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}