A Chinese firm on the U.S. Entity List claimed to have built its own take on Anthropic’s bug-busting Mythos AI model.
According to Reuters, the Beijing-headquartered Qihoo 360 unveiled two AI models - Tulongfeng and Yitianzhen - with the latter described by company founder and CEO Hongyi Zhou as "China's version of Mythos."
In claims yet to be independently verified, Zhou said 3,432 software vulnerabilities had been found using Tulongfeng across open-source code, binary software, and AI/agentic systems. According to the CEO, the tool was trained on 360’s database of 250,000 vulnerabilities accumulated since its inception in 2005.
This is in comparison to Claude Mythos Preview, which Anthropic claimed generated over 23,000 findings across more than 1,000 open-source projects, including over 6,200 it estimated as high or critical. Its partners on Project Glasswing - the taskforce with exclusive use of Mythos’ full capabilities, which includes Cisco and Palo Alto Networks - meanwhile have identified more than 10,000 serious flaws to date.
Where Zhou described Mythos as an automated vulnerability researcher relying on “the strongest model, the strongest computing power and the strongest chips," Tunlongfeng is instead an orchestrated vulnerability-research platform built with a software-first approach, specifically around AI agents. He argued this better suits China, where he claimed domestically developed AI models lag behind those from the U.S. by 20%-30% in underlying capabilities.
In remarks made at the ISC.AI 2026 cybersecurity conference in Beijing, Zhou argued China cannot afford to wait for its models to develop, hence the need for a fully sovereign take on Mythos.
Zhou compared Anthropic’s most powerful frontier model to a “nuclear weapon,” adding: “Why has nuclear war never actually broken out? Because everyone possesses nuclear weapons, allowing for mutual deterrence. The same applies to cybersecurity. If others have them, so do I; I won't be passively attacked.”
AI sovereignty in cybersecurity
The CEO may be extra sensitive to geopolitical affairs, considering Qihoo 360 was one of the Chinese companies placed on the Bureau of Industry and Security's Entity List in 2020. The firm was accused of "enabling China’s high-technology surveillance" in the alleged crackdown on Uyghurs in Xinjiang.
Tulongfeng’s warfare framing was exemplified by its release coming under the product banner of "Yitian Tulong", translating to "Heavenly Sword and Dragon Saber,” the name of a classic martial arts text. Within the suite, the model works in tandem with Yitianzhen, an automated cyber-defense system intended to operate as an AI-driven security operations center (SOC) layer. In 360's literary context, Tulongfeng translates as the tip of the dragon saber, while Yitianzhen refers to a cluster sword formation.
In uncanny timing, Tulongfeng’s release came as Anthropic accused Chinese tech giant Alibaba of "brazenly" and "illicitly" extracting capabilities from its mainline series of Claude models.
As recently explored by SDxCentral, Anthropic itself has not been immune to geopolitical issues. The firm’s latest Mythos 5 and Fable 5 models were banned from export this month by the U.S. government due to an alleged method of “jailbreaking” Fable 5, with potential repercussions for national security.
The ban was partially rescinded last week, with a select group of 100-plus companies and agencies granted access to the Mythos 5 model. Fable 5, though, remains blocked.
Security experts such as Laura Wilber, senior analyst, office of the CTO at Swedish specialist Enea, said the move “added yet more fuel to the digital sovereignty fire in Europe, which will no doubt mean more funding flowing to the EU’s leading homegrown commercial LLM, Mistral.”
Comments