Particle.news

CISA Uses Anthropic’s Mythos to Scan Federal Code

The move signals growing government reliance on powerful AI to find software flaws despite ongoing disputes over access and safeguards.

Overview

  • Reuters reported Monday that the Cybersecurity and Infrastructure Security Agency is running Anthropic’s Mythos model to scan government code repositories for security bugs.
  • The work is being carried out by CISA’s Attack Surface Evaluation team, a unit that conducts simulated hacking exercises and security assessments across federal systems.
  • Two sources told reporters that Mythos-driven audits have already uncovered a large number of vulnerabilities but the agencies have not disclosed how much code was reviewed or how serious the flaws are.
  • CISA secured full Mythos access under Anthropic’s Project Glasswing after the model was privately shared with intelligence agencies that tested it in April, and the step follows a months-long dispute that included a Pentagon supply-chain designation later blocked by a judge.
  • The deployment highlights tensions between operational gains and transparency concerns and raises questions about export controls, who may access such models, and how fast AI will change government cybersecurity practices and public oversight.