IC Technology & Surveillance — 2026-07-07

CISA Deploys Anthropic Mythos AI to Audit Government Code Repositories for Security Vulnerabilities

BLUFScaling automated vulnerability discovery across government repositories without a commensurate surge in remediation capacity risks building a classified backlog that adversaries would prize more than any single exploit.

CISA is using Anthropic's Mythos AI model to audit government software, three people familiar with the matter told Reuters 1. The Attack Surface Evaluation team, a unit that runs digital security assessments across government, is conducting the scans, checking code repositories for bugs that could expose systems to foreign spies and cybercriminals, one source said 1. Two sources said the audits have already uncovered a large number of vulnerabilities, though Reuters could not establish how much code has been reviewed or the severity of the bugs found 1. The initiative comes as Anthropic's relationship with the government has been strained since February, when the Pentagon imposed a formal supply-chain risk designation on the company over its refusal to strip safeguards blocking use of its AI for autonomous weapons or domestic surveillance; a judge blocked that designation in March, and tensions have eased since the private release of Mythos 1. Anthropic did not respond to questions about the initiative, and a CISA representative who said last month he would check on the matter did not respond to further emails 1.

Analysis
CISA's use of Mythos to scan government repositories extends Anthropic's vulnerability-discovery model beyond the NSA's classified testing into an operational, cross-government security function, giving the Attack Surface Evaluation team a scaled capability for surfacing bugs faster than agencies can patch them. Moderate confidence in this assessment rests on Reuters' three sourced accounts, which converge on the program's scope without official confirmation from either agency. Persistent non-response from both CISA and Anthropic, even as adoption widens, indicates the program's disclosure posture remains deliberately closed. The volume of vulnerabilities already found, undisclosed in scope or severity, means discovery may outpace remediation capacity across the audited repositories.
5 sources
  1. Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say - Reuters
  2. US cyber agency is using Anthropic's Mythos to audit government code, sources say - BusinessWorld Online
  3. Exclusive-US cyber agency is using Anthropic's Mythos to audit government code, sources say - The Star (Malaysia)
  4. US cyber agency is using Anthropic's Mythos to audit government code, sources say - Arab News
  5. Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say - Reuters

View in full brief →

UNCLASSIFIED // OPEN SOURCE