IC Technology & Cyber — 2026-07-10

CISA Deploys Anthropic Mythos AI to Scan Federal Code for Vulnerabilities Ahead of Foreign Intelligence Services

BLUFCISA's use of Mythos against public GitHub repositories creates a race between federal patching timelines and foreign services running comparable AI tools against the same exposed code.

CISA's Attack Surface Evaluation team is running Anthropic's Mythos AI model against federal code repositories on GitHub to identify vulnerabilities, according to a Reuters report citing three unnamed sources and a CISA employee who confirmed the effort to Forbes 12. Two sources told Reuters the scans have already uncovered a "large number" of vulnerabilities, though the scope of code reviewed and severity of the flaws found have not been disclosed 1. Neither CISA nor Anthropic responded on the record to Reuters or Forbes queries about the initiative 12. Forbes reported that CISA had previously lacked access to Mythos, which Anthropic has limited to roughly 50 select partner organizations; how CISA obtained permission to use it is unclear 2. The deployment follows NSA's use of Mythos since at least April despite an ongoing Pentagon supply-chain risk designation against Anthropic that a federal judge blocked in March 13.

Analysis
CISA's use extends Mythos from classified NSA testing into an operational, cross-agency role scanning public GitHub repositories, widening the aperture from signals-intelligence systems to routine federal software. Undisclosed scope and severity of vulnerabilities already found leaves agencies unable to gauge patching burden or exposure risk before the same repositories draw outside probing, and neither party's on-record silence explains how CISA gained access outside Anthropic's roughly fifty-partner cohort or what safeguards govern the expansion. Reuters furnishes the lone primary account, with Security Affairs, SecurityWeek, and Forbes offering secondary amplification rather than independent corroboration. The access may reflect an informal arrangement by individual Attack Surface Evaluation staff rather than a sanctioned, agency-wide partnership between CISA and Anthropic.
4 sources
  1. Exclusive-US Cyber Agency Is Using Anthropic's Mythos to Audit Government Code, Sources Say - Reuters (via U.S. News & World Report)
  2. A US Cyber Agency Is Finally Using Anthropic's Mythos - Forbes
  3. CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code - Security Affairs
  4. CISA Reportedly Using Anthropic's Mythos to Scan Government Software for Flaws - SecurityWeek

View in full brief →

UNCLASSIFIED // OPEN SOURCE