CISA Deploys Anthropic Mythos AI to Scan Federal Code for Vulnerabilities Ahead of Foreign Intelligence Services
CISA's
CISA's use extends Mythos from classified NSA testing into an operational, cross-agency role scanning public GitHub repositories, widening the aperture from signals-intelligence systems to routine federal software. Undisclosed scope and severity of vulnerabilities already found leaves agencies unable to gauge patching burden or exposure risk before the same repositories draw outside probing, and neither party's on-record silence explains how CISA gained access outside Anthropic's roughly fifty-partner cohort or what safeguards govern the expansion. Reuters furnishes the lone primary account, with Security Affairs, SecurityWeek, and Forbes offering secondary amplification rather than independent corroboration. The access may reflect an informal arrangement by individual Attack Surface Evaluation staff rather than a sanctioned, agency-wide partnership between CISA and Anthropic.
4 sources
- Exclusive-US Cyber Agency Is Using Anthropic's Mythos to Audit Government Code, Sources Say -
Reuters (via U.S. News & World Report) - A US Cyber Agency Is Finally Using Anthropic's Mythos -
Forbes - CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code -
Security Affairs - CISA Reportedly Using Anthropic's Mythos to Scan Government Software for Flaws -
SecurityWeek