China's largest cybersecurity firm has made its boldest move yet in the global AI security race. 360 Security Technology unveiled an AI-powered vulnerability discovery tool called "Tulongfeng," which founder Zhou Hongyi explicitly described as "China's version of Mythos," referencing Anthropic's own automated vulnerability-detection system that has triggered alarm in Washington since its preview earlier this year.
What Was Announced
Speaking at the ISC.AI 2026 cybersecurity conference in Beijing, 360 founder Zhou Hongyi unveiled two AI security tools under the banner "Yitian Tulong," a name drawn from a classic Chinese martial arts novel meaning "Heavenly Sword and Dragon Saber". Zhou said one tool, "Tulongfeng," was designed to automatically discover software vulnerabilities, calling it "China's version of Mythos," while a second system, "Yitianzhen," was built to automate cyber defence and incident response.
Zhou framed the release in explicitly strategic terms, arguing that such capabilities shouldn't be the domain of a single country. "This kind of powerful weapon that can change the landscape of cyber offence and defence cannot be held only by others," Zhou said in a speech, according to a transcript published by 360. He described vulnerability-finding AI as a national strategic asset that could be used both to defend critical infrastructure and to gain offensive advantage.
The Context: Why Mythos Matters
The comparison to Mythos isn't incidental — it's a direct response to a system that's already reshaped global conversations about AI and cybersecurity. Mythos, previewed in April, is a system that detects software vulnerabilities, but cybersecurity experts have warned that it could supercharge cyberattacks. The U.S. this month ordered Anthropic to suspend exports of a less powerful version of the programme, citing national security concerns. Anthropic said in April that Mythos Preview had found "thousands" of major vulnerabilities in operating systems, web browsers, and other software, a scale of capability that immediately drew scrutiny from governments and security researchers alike.
360's release represents the most prominent Chinese response to that capability gap to date. 360's release marks the most high-profile Chinese answer yet to Anthropic's Mythos model, which has triggered alarm in Washington and other capitals, as well as across the cybersecurity industry, over its ability to discover vulnerabilities in sensitive systems.
Zhou's "Agent" Strategy: Compensating for a Capability Gap
Notably, Zhou didn't claim parity with US frontier models — he acknowledged a real gap and described a workaround. "Objectively speaking, domestic models still have a 20%-30% gap in base capability," Zhou said. "China cannot wait until model capabilities have fully caught up before starting vulnerability discovery, because we cannot afford to wait".
His solution was to compensate for weaker underlying models with heavier engineering around them. Zhou's argument was that China cannot afford to wait for that gap to close, so instead 360 took an "agent" approach, focused on layering AI models on already existing security expertise, vulnerability databases, and automated tooling, which he claimed gives Tulongfeng capabilities equivalent to Mythos despite using less powerful underlying models. He summarized the philosophy with a vivid analogy: "If Mythos is a top-end chip, what we are building is a complete machine that can run stably, work 24 hours a day and make fewer mistakes," he said. "If the U.S. route is to cultivate a genius hacker, 360's route is to organise a professional attack-and-defence team".
The Numbers 360 Is Citing
360 has pointed to concrete results to back its claims of capability. 360 claimed Tulongfeng had identified 3,432 software vulnerabilities so far, with 105 confirmed by Chinese authorities. Earlier in April, the company reported that its AI-driven methods detected about 1,000 vulnerabilities in systems including Microsoft Office. These figures, while unverified by independent third parties, are being used to support 360's broader claim that an agent-based, lower-compute approach can approximate frontier-model performance in this specific domain.
A Defensive Initiative Alongside the Offensive Capability
Beyond Tulongfeng itself, 360 is also positioning a broader defensive ecosystem around the technology. 360 also plans to release the automated defense system "Yitian Array," aiming to connect vulnerability discovery, verification, patching, and defense responses into a more automated process. "The only way out is to fight computing power with computing power, intelligence with intelligence, machine against machine, enabling China's defense to shift from manpower to autopilot," Zhou summarized. At the same time, 360 and 20 key domestic digital infrastructure providers have launched the "Rock Shield" initiative, seeking to proactively establish a vulnerability screening mechanism for critical domestic software and hardware.
A Broader Geopolitical Backdrop
This announcement lands amid a long-running pattern of mutual suspicion between Washington and Beijing over cyber capabilities. China and the U.S. have a long history of accusing each other of conducting offensive cyber operations on critical infrastructure. Zhou also warned against the risk of "one-way transparency," where US entities could use Mythos-like models to probe software and critical systems while Chinese companies were denied similar capabilities — a framing that positions Tulongfeng as much as a matter of strategic parity as a technical achievement.
For ongoing, authoritative coverage of how AI is reshaping global cybersecurity dynamics, the US Cybersecurity and Infrastructure Security Agency's news desk remains a key resource for tracking how governments are responding to these dual-use AI capabilities.
What This Means Going Forward
360's announcement underscores a broader truth about AI-driven cybersecurity: capabilities that can find software flaws are inherently dual-use, equally valuable for defenders patching systems and attackers exploiting them before anyone else notices. As both the US and China continue racing to develop and control these tools, expect continued export restrictions, competing claims of technical parity, and growing pressure on the broader cybersecurity industry to adapt to a landscape where vulnerability discovery itself has become an instrument of national strategy.