Adversary Intelligence — 2026-06-30
Sanctioned Chinese Firm Qihoo 360 Announces Tulongfeng AI Cyber Weapon as Answer to Anthropic Mythos Comparing Vulnerability Discovery to Nuclear Deterrence
BLUFChina's mandatory disclosure law already converts every Tulongfeng-confirmed zero-day into a state asset before vendor notification, while independent verification of the system's actual capabilities remains very unlikely before mid-2027.
At ISC.AI 2026 in Beijing on June 24, Qihoo 360 founder Zhou Hongyi unveiled Tulongfeng and Yitianzhen, describing Tulongfeng as China's answer to Anthropic's Mythos and comparing AI vulnerability-discovery capabilities to nuclear deterrence 123. Zhou claimed Tulongfeng has flagged 3,432 software flaws since deployment, with 105 confirmed by Chinese government authorities, while acknowledging a 20 to 30 percent capability gap versus U.S. frontier models 12. No independent benchmarks have been released, and ETH Zurich researcher Eugenio Benincasa concluded Qihoo's AI capabilities do not yet match Mythos's autonomous reasoning 2. Under China's Data Security Law, every vulnerability Tulongfeng confirms must be reported to Beijing within 48 hours, before vendor notification or public disclosure 2.
AnalysisZhou's deterrence framing breaks on a structural asymmetry China's Data Security Law makes unavoidable. Every zero-day Tulongfeng confirms must reach Beijing within 48 hours, before vendor notification, converting each discovery into a state intelligence asset regardless of stated defensive intent or capability parity. That pipeline is operational today. Independent peer-reviewed evaluation of Tulongfeng's capabilities is
very unlikely before June 30, 2027, given Qihoo's entity-list restrictions and the absence of any incentive to expose proprietary research to outside scrutiny. Confidence is moderate: Benincasa's April analysis remains the only named external technical judgment, and no benchmarks subject to independent replication exist. The announcement may serve domestic politics as much as operational signaling, and a sanctioned firm has strong incentives to signal strategic relevance regardless of verified performance. Critical infrastructure organizations must treat the Chinese state vulnerability pipeline as a live threat regardless of any Mythos parity verdict.
4 sources
- Chinese cybersecurity company 360 unveils 'China's version of Mythos', and Yitianzhen, to automate cyber defense - TechRadar
- China Builds AI Vulnerability Scanner to Counter Mythos: Every Zero-Day Goes to Beijing by Law - TechTimes
- China Announces Its Answer to Mythos With Its Own Cyber Weapon of Mass Destruction - Security Boulevard
- Chinese cybersecurity company claims it's built a better-than-Mythos bug finder - The Register
View in full brief →