Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
CISA Went From Locked Out of Mythos in April to Full Access by June. Here Is What the Model Found.

Since the Anthropic-Pentagon dispute escalated in February 2026, CISA has gone from being locked out of Mythos entirely to operating it against sensitive government code, according to reporting by Reuters on July 6.
The specifics of that shift merit close attention. The two accounts don't fully line up.
How CISA Got Access
When Anthropic briefed CISA and the Commerce Department on Mythos Preview back in April 2026, CISA was not included in the initial access group of roughly 50 organizations, according to Crypto Briefing. By mid-June, that had changed. Anthropic's Project Glasswing initiative, which the company describes as a program to expand code analysis across critical infrastructure and government sectors, added approximately 150 additional partner organizations across more than 15 countries in early June. CISA gained full access shortly after that expansion, according to Crypto Briefing.
Reuters, citing three people familiar with the matter, reported that CISA's Attack Surface Evaluation team — the unit that runs digital security assessments and hacking exercises across federal agencies — is now using Mythos to scan government code repositories for vulnerabilities. Two of those sources said the audits have already uncovered a large number of vulnerabilities. Reuters could not establish the scope of code reviewed, the number of bugs found, or their severity. Anthropic declined to comment. A CISA representative told Reuters he would look into whether information could be shared but did not follow up.
What the Model Is Capable Of
The capability gap between Mythos and conventional code review tools is not theoretical. Anthropic's own published assessment found the model capable of discovering vulnerabilities that had survived decades of human-led review across major operating systems and browsers, then building working exploits without human guidance. SecurityWeek reported the tool flagged more than 23,000 potential vulnerabilities across more than 1,000 open-source projects. Independent security firms reviewed 1,900 of those findings and confirmed 1,726, with more than 1,000 rated high or critical severity, according to that reporting.
During testing with intelligence agencies, the model reportedly uncovered vulnerabilities in classified systems within hours, according to Crypto Briefing. Traditional timelines for that kind of work run weeks at minimum.
The Contradiction Nobody Is Explaining
This deployment sits inside a genuinely strange institutional contradiction. In February 2026, Defense Secretary Pete Hegseth designated Anthropic a supply chain risk under the Federal Acquisition Supply Chain Security Act after contract negotiations collapsed over Claude's acceptable-use provisions, specifically Anthropic's refusal to remove language barring fully autonomous weapons systems and mass domestic surveillance. President Trump ordered agencies to cut ties. The General Services Administration removed Anthropic from USAi.gov and its government-wide contracting schedule days later.
An appeals court sided with the Pentagon's designation in April, according to CNBC. Anthropic had sued after a judge initially blocked the designation in March, according to CNN.
Yet the National Security Agency had already been running Mythos since April, Reuters reported, during the same period the blacklist was nominally in effect. Now CISA has full access. Startupfortune noted the same irony directly: this is the same government that ordered agencies to stop using Anthropic's AI in February.
The Case for Proceeding Anyway
No other commercially available model has Mythos's documented track record on vulnerability discovery at scale. Federal code is a target for Chinese and Russian intelligence services right now, not at some future policy-resolved date. If the tool finds a critical vulnerability in a classified system this week that a human team would have found in three months, the operational argument for using it is real regardless of the contract dispute. Critics of the Pentagon's position would argue that pulling the best available tool off the job because of a procurement fight is exactly the kind of bureaucratic dysfunction that gets people hurt.
That argument deserves to be stated fairly. It does not resolve the underlying question of whether executive orders mean what they say.
The Open Risk Nobody Is Accounting For
Project Glasswing's expansion to more than 15 countries introduces a dimension the current coverage is mostly skipping. The same model auditing U.S. government code is now accessible to international partner organizations, according to Crypto Briefing. That creates shared defensive capability and shared knowledge of what the model can find and how it finds it. Whether those international partners operate under the same security requirements as CISA is not addressed in any of the available reporting.
The other unresolved exposure: a running list of unpatched federal vulnerabilities, wherever it lives, is itself a target. The sources who spoke to Reuters confirmed bugs were found. Neither they nor CISA has said where those findings are stored, who has access to them, or what the remediation timeline looks like.
The next concrete marker to watch is whether other civilian agencies replicate the CISA template under Project Glasswing, and whether any of them are willing to say so publicly while the Pentagon's supply chain designation is still being litigated.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.