The US cyber defense agency CISA is using Anthropic's AI model "Mythos" to scan government program code and uncover vulnerabilities, according to a July 6, 2026 report citing three people familiar with the matter.
July 6, 2026 · CISA × Anthropic
A US Cyber Agency Turns a "Too Dangerous to Release" AI Loose on Government Code
CISA is running Anthropic's Claude Mythos 5 — a model held back from public release over its zero-day-finding power — to hunt vulnerabilities across federal code repositories. Sources say a large number of flaws have already surfaced.
10,000+
High/critical vulnerabilities found early in Project Glasswing
~150
Trusted-partner organizations with access (AWS, Apple, Google, NATO…)
73%
UK AISI expert-level cyber task success rate
Cyber Benchmark Leap
Mythos 5 vs the prior Opus 4.6 on the cyber-specific benchmark
+16.5 points on cyber capability — the gain that made it "trusted partners only"
$10 / $50
Per M input / output tokens
Defensive Upside
Real track record finding flaws in critical software
Edge confirmed in CTF and multi-step attack scenarios
Faster, more efficient government code auditing
The Dual-Use Worry
Same zero-day skills can be repurposed for attacks
Withheld from public release; guardrailed "Fable 5" offered instead
Scope, severity and fix status all undisclosed
A Tense Government Relationship
Feb 2026
Pentagon issues supply-chain risk flag after Anthropic refuses to drop guardrails (later blocked in court)
→
Late Jun 2026
Export controls on Mythos and Fable lifted
→
Now
CISA — and reportedly the NSA — deploy Mythos on federal code
Continue reading The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in ✓ Signed in — this article isn’t included in your current plan.Unlocking the full article…