Chinese cybersecurity company claims it's built a better-than-Mythos bug finder

lukewarm7071 pts0 comments

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder

Jump to main content

Search

REG AD

Security

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder

Qihoo 360, which the US has banned, says it’s needed as a deterrent to weaponized Anthropic models

Simon Sharwood

Simon<br>Sharwood

APAC Editor

Published<br>fri 26 Jun 2026 // 02:49 UTC

Chinese cybersecurity vendor Qihoo 360 claims it’s built an AI bug-finder that’s better than Anthropic’s Mythos model.<br>CEO Zhou Hongyi revealed the model in a speech at the 14th Beijing Cybersecurity Conference, which Qihoo 360 organizes. Chinese media outlets have transcribed the talk, in which Zhou described Mythos as “equivalent to a ‘cyber nuclear weapon’,” because the USA’s ban on foreign nationals accessing the model gives America a tool with which to find flaws in software upon which other nations rely.<br>Zhou thinks China needs equivalent capabilities as a deterrent, but suggested replicating Mythos is not a viable approach.

REG AD

“Mythos follows a typical large-scale model approach: the strongest model, the strongest computing power, and the strongest chips – a strategy of sheer brute force,” he said. “However, this path has an implicit prerequisite: your model capabilities must be sufficiently strong. Objectively speaking, domestically developed models still lag behind by 20 percent to 30 percent in underlying capabilities.”

REG AD

The CEO therefore thinks China can’t wait for its own models to catch up and needs to find another way to build Mythos-grade bug-finders.<br>Helpfully, Qihoo 360 has found those alternative methods by distilling its 20 years of experience fighting cyber-threats and colossal malware library into security-specific models and agents. The company has put that to work in what Zhou described as a “multi-agent swarm.”

MORE CONTEXT

Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era

Five Eyes spooks warn AI means infosec incidents can become ‘major operational and financial crises’

Anthropic's Mythos mess just keeps getting more complicated

Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher

“If the American approach is about cultivating a genius hacker, the 360 approach is about organizing a professional attack and defense team,” he said. “When faced with a target, the swarm doesn't perform single-point analysis, but rather collaborates: first, it models the threat and filters high-risk attack surfaces; then, it follows the data flow across files to discover potential vulnerabilities.”<br>The company’s agents apparently “automatically build sandbox environments, automatically generate exploit code, and conduct real-world testing. The result is that every vulnerability is ‘confirmed’ rather than just suspected. After completing a task, the swarm also summarizes and reviews its performance, becoming smarter with each use. This is something a single large model can hardly do.”<br>Qihoo calls this approach “Tulongfeng” and says it’s already finding flaws in open-source and commercial software.<br>“We automatically discovered a Windows kernel privilege escalation vulnerability that had been dormant for five years, an Office remote code execution vulnerability that had been dormant for eight years, and an Excel vulnerability that had been dormant for 10 years, earning official recognition from Microsoft,” Zhou boasted. The CEO said the tool found plenty of flaws in OpenClaw – a feat that human researchers have also achieved.<br>Zhou said Qihoo 360 has created another AI-powered security tool called “Yitianzhen” that automatically simulates potential attacks against an organization’s cyber-defenses, then suggests and/or implements remediations. The company has created an alliance of local cybersecurity companies to use it and create a bulwark against Project Glasswing – the group of entities Anthropic allows to use Mythos under controlled conditions.<br>US authorities have sanctioned Qihoo 360 on grounds that it probably supplies China’s military. China's National Computer Virus Emergency Response Center (CVERC) often cites and publicizes the company’s research, sometimes in its documents that allege the US hacks itself to make China look bad. ®

china<br>anthropic mythos<br>ai and ml<br>security

REG AD

security

Security boss thought MFA would be too much security

One rule for the workers, another for execs

OS PLATFORMS

Microsoft extends extended updates for Windows 10 in the most muted way imaginable

Tiny tweak to support page reveals consumers can purchase another year of patch protection

ZTE builds a TCO-optimal AI factory to fuel token economy

PARTNER CONTENT: Leveraging OEX architecture SuperPODs and multi-dimensional co-design to maximize tokens per second and lower total cost of ownership for scaled inference

Security

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder

Qihoo 360, which the...

mythos company security qihoo cybersecurity model

Related Articles