Overview
- CISA’s Attack Surface Evaluation team is running Anthropic’s Mythos to scan government code repositories, three people familiar with the matter told reporters on Monday.
- Sources said the audits have already uncovered a large number of vulnerabilities, though CISA and Anthropic have not disclosed how many or how severe the flaws are.
- CISA gained full access to the Mythos Preview model under Anthropic’s Project Glasswing after the program expanded to roughly 150 partner organizations in early June.
- The National Security Agency tested Mythos in classified settings earlier this year and reported rapid results, and the deployment follows a recent temporary shutdown and White House demands over foreign access to the model.
- Officials face tradeoffs: faster, AI-driven bug hunting could harden government systems quickly, but it also raises unresolved questions about supply-chain trust, export controls, foreign partners’ access, and independent oversight.