CISA Deploys Anthropic Mythos AI to Audit Government Code Repositories for Security Vulnerabilities
CISA is using Anthropic's
CISA's use of Mythos to scan government repositories extends Anthropic's vulnerability-discovery model beyond the NSA's classified testing into an operational, cross-government security function, giving the Attack Surface Evaluation team a scaled capability for surfacing bugs faster than agencies can patch them. Moderate confidence in this assessment rests on Reuters' three sourced accounts, which converge on the program's scope without official confirmation from either agency. Persistent non-response from both CISA and Anthropic, even as adoption widens, indicates the program's disclosure posture remains deliberately closed. The volume of vulnerabilities already found, undisclosed in scope or severity, means discovery may outpace remediation capacity across the audited repositories.
5 sources
- Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say -
Reuters - US cyber agency is using Anthropic's Mythos to audit government code, sources say -
BusinessWorld Online - Exclusive-US cyber agency is using Anthropic's Mythos to audit government code, sources say -
The Star (Malaysia) - US cyber agency is using Anthropic's Mythos to audit government code, sources say -
Arab News - Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say -
Reuters