Artificial Intelligence

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises.

Claude Mythos

The US Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s powerful Mythos AI model to scan and audit federal government software for security vulnerabilities, according to a report from Reuters.

Citing three sources familiar with the matter, Reuters reported that CISA is utilizing Mythos to scan code repositories across federal agencies. The operation aims to proactively discover and patch security bugs that could otherwise be exploited by foreign intelligence agencies and cybercriminals.

The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises across the federal landscape. Two sources stated that the AI-driven initiative has already uncovered a “large number” of software vulnerabilities. However, specific details regarding the severity of the flaws, the impacted agencies, or the volume of software reviewed have not been disclosed.

Neither Anthropic nor CISA provided formal on-the-record comments to Reuters regarding the operation.

Tensions between Anthropic and federal officials spiked dramatically earlier this year after the company refused administration demands to remove built-in safeguards restricting its models from being used for autonomous weaponry or domestic surveillance. In response, the Pentagon designated Anthropic as a supply-chain risk, a classification typically reserved for foreign firms suspected of espionage.

The National Security Agency (NSA) is also believed to be using Mythos in its operations.

Advertisement. Scroll to continue reading.

Late last month, a US official told the Associated Press (AP) that one of Anthropic’s artificial intelligence models had identified vulnerabilities in highly sensitive and secure US government computer systems during a testing exercise.

While the private application of Mythos has accelerated within the US intelligence and defense communities, Anthropic’s public-facing rollouts have triggered separate regulatory battles. When the company launched its public version of the model in early June, called Fable, concerns from the White House regarding foreign nationals accessing the tool prompted an abrupt administrative demand to restrict access. The ensuing standoff led to a temporary global shutdown of the Fable model, which was only lifted last week.

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

RelatedOpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review

RelatedWhen Information Becomes the Attack Surface – Understanding AI Agent Traps

Related Content

Artificial Intelligence

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. 

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Artificial Intelligence

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.

Artificial Intelligence

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.

Artificial Intelligence

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous...

Artificial Intelligence

Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture”...

Artificial Intelligence

The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version