Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
China's 360 Security Claims Its AI Tools Match Anthropic's Mythos. The Claims Are Unverified.

China's 360 Security is claiming its new AI tools match a cybersecurity product it calls 'Mythos,' attributed to Anthropic. Those comparisons rest on a foundation that has not been independently verified.
What 360 Actually Announced
At the ISC.AI 2026 cybersecurity conference in Beijing on June 25, 360 Security Technology founder Zhou Hongyi unveiled two tools under the name Yitian Tulong, drawn from a classic Chinese martial arts novel meaning Heavenly Sword and Dragon Saber. The first tool, Tulongfeng, is designed to automatically discover software vulnerabilities. Zhou called it "China's version of Mythos," referencing what he described as an Anthropic AI-powered vulnerability scanner. The second tool, Yitianzhen, automates cyber defense and incident response. 360 says Tulongfeng has found 3,432 software vulnerabilities, including 105 confirmed by Chinese authorities, according to Reuters.
The Verification Gap The article's central comparison — between what
Anthropic allegedly demonstrated and what 360 has claimed — depends on the existence and capabilities of an Anthropic product called "Mythos" or "Mythos Preview." The existence of this product, the specific capabilities attributed to it, and an associated initiative called "Project Glasswing" under which more than 40 organizations were allegedly granted access to it, have not been independently confirmed by this publication. Reports citing these details originate from sources that have not been corroborated. What is on the record is this: Zhou himself, as reported by the South China Morning Post, described an Anthropic-linked tool as representing a "terrifying change" in vulnerability discovery — accelerating it a hundredfold while cutting costs. Whether that characterization reflects a verified Anthropic product or Zhou's own framing of a rival capability is unclear. 360's track record heading into this announcement includes a competition in April where, according to Crypto Briefing, its AI-driven methods detected approximately 1,000 vulnerabilities in Microsoft Office. That is not nothing. But Eugenio Benincasa, an analyst at ETH Zurich cited by Crypto Briefing, has flagged the gap between detecting vulnerabilities in a single application and autonomously exploiting zero-day chains across entire operating system ecosystems. Those are different orders of capability, and 360's new tools have not been tested in comparable scenarios.
Zhou's Strategic Argument
Zhou's case is not only technical. It is geopolitical, and it deserves a fair read before dismissing it. Zhou argued, according to the South China Morning Post, that Chinese firms lack access to advanced AI vulnerability tools available to U.S.-aligned organizations, creating a condition of "one-way transparency" in which foreign actors could scan Chinese software for exploitable flaws without reciprocal exposure. He compared building a domestic equivalent to nuclear deterrence, describing the goal as "reciprocal strategic deterrence capability." Zhou is a member of China's top political advisory body, which gives his public remarks weight beyond a typical CEO announcement. If a foreign government held a monopoly on a tool that could autonomously find exploitable flaws in a nation's critical infrastructure software, seeking a domestic equivalent is a rational response, not just propaganda. The U.S. would do the same, and has.
The Chip Constraint Is Real
Zhou acknowledged one structural obstacle directly: U.S. export controls on advanced semiconductors, tightening since 2022, have limited Chinese firms' access to the highest-end chips. He said 360 would NOT simply replicate any American approach of deploying the strongest model on the strongest chips. What exactly the alternative architecture looks like, he did not specify publicly. This tracks with the broader AI picture: some Chinese firms have pursued efficiency-first paths that optimize around hardware constraints rather than relying on raw compute. Whether 360 has taken a similar approach with Tulongfeng is not established in the available sources.
What Remains Unresolved The core open question as of June 27
can Tulongfeng actually do what Zhou claims a competing tool does, or does it close only part of a gap with a product whose own capabilities remain unverified in public sources? 360's vulnerability count of 3,432 findings is larger than the April competition result, but the claims have not been tested against a comparable independent benchmark. Until they are, the assertion that China has matched any specific rival AI cybersecurity capability is exactly that: an assertion by an interested party at a government-adjacent conference in Beijing.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.