
A U.S. official has confirmed that Anthropic's Mythos AI model successfully identified vulnerabilities in highly sensitive and secure U.S. government computer systems during a testing exercise. According to The Associated Press, the official, who spoke on condition of anonymity, revealed that Anthropic had teamed up with U.S. intelligence agencies to conduct these tests using the company's Mythos model. The official noted that while the model identified certain vulnerabilities within hours, this does not mean the model was able to exploit them within that timeframe. The testing was conducted through Anthropic's Project Glasswing initiative, which brought together tech giants and other companies in hopes of securing the world's critical software from potential fallout.
CISA's Attack Surface Evaluation team, which runs digital security assessments and hacking exercises across government, is using the AI to comb through government code repositories for vulnerabilities that could be exploited by foreign spies or cybercriminals. As reported by Reuters and Devdiscourse, the agency's Attack Surface Evaluation team is responsible for conducting these comprehensive security assessments across government systems. The team has already detected numerous vulnerabilities during their scans, though specific details about the scope and nature of these vulnerabilities remain undisclosed. Democratic Sen. Mark Warner of Virginia had briefly mentioned the testing during a June 11 hearing before the Senate Committee on Banking, Housing, and Urban Affairs, stating that 'This tool broke into almost all of our classified systems, not in weeks but in hours.'
According to sources familiar with the matter, two of the sources said the audits had already uncovered a large number of vulnerabilities, though they did not elaborate further on the specific details. The agency stated it could not independently verify the extent of the code reviewed or the severity of the bugs identified, as reported by Reuters. Sen. Warner attributed the information to Gen. Joshua Rudd, head of the National Security Agency and U.S. Cyber Command, during his Senate testimony. The testing represents a significant development in government AI security implementation, demonstrating the effectiveness of AI-powered vulnerability detection in critical infrastructure protection.
Despite the recent cooperation between Anthropic and U.S. agencies for security testing, tensions between the California company and the Trump administration have been growing. The administration issued a directive earlier this month requiring Anthropic to prevent foreign nationals from using its latest artificial intelligence models, known as Fable 5 and Mythos 5. Anthropic released Fable widely earlier this month, which is a limited version of the more advanced Mythos model, to which the company has tightly limited access due to cybersecurity fears. The directive came 10 days after President Donald Trump signed an executive order to establish a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. Anthropic said it disabled the models for all of its customers to comply with the administration's directive, stating it did not believe the steps taken by the government were warranted by the concern it flagged about a potential security issue.