Chinese cybersecurity company 360 Security Technology has unveiled a pair of AI security tools it says can go head-to-head with Anthropic's Mythos model, framing the US-built system as a strategic threat that Beijing cannot afford to leave unanswered. The announcement, reported by Reuters on June 24, 2026, comes as an American export ban continues to block global access to Anthropic's most powerful cybersecurity-focused models.

At a Beijing event called ISC.AI 2026, 360 founder Zhou Hongyi introduced the tools under the collective name "Yitian Tulong," a reference to a well-known Chinese martial-arts epic. The first tool, Tulongfeng, is designed for automated vulnerability discovery in software, while the second, Yitianzhen, focuses on streamlining cyber defense and incident response. For more context on this story, see our ongoing breaking AI news.

A Deliberate Counter to Mythos

Anthropic introduced Mythos in April 2026 as an AI system capable of autonomously identifying flaws in widely used software. The company reported that an early version had uncovered thousands of serious vulnerabilities spanning operating systems, browsers, and other applications. Security researchers cautioned at the time that the same capabilities could be turned toward offensive use.

360 positioned its new tools as a direct response. According to a speech transcript published by the company, Zhou told the audience that "this kind of powerful weapon that can change the landscape of cyber offence and defence cannot be held only by others." The remark captures a growing anxiety in Beijing that cutting-edge AI for security could become a one-way street, available to American actors probing Chinese systems but not vice versa.

That concept, which Zhou labeled "one-way transparency," sat at the center of his argument. He warned that tools like Mythos could allow American actors to probe Chinese infrastructure at will while China remained unable to respond in kind, casting AI-driven vulnerability discovery as an asset with implications for both shielding critical systems and pursuing offensive operations.

Reported Findings and a Conceded Gap

360 said Tulongfeng had already found 3,432 software vulnerabilities, including 105 confirmed by Chinese authorities. Reuters noted that it could not independently verify those claims. The company also laid out the results of what it characterized as head-to-head benchmarking against Mythos.

Strikingly, 360 was candid about the limits of Chinese foundation models. "Objectively speaking, domestic models still have a 20% to 30% gap in base capability" compared with US systems, Zhou said, according to the transcript. Rather than wait for parity, his answer was to layer AI models on top of 360's proprietary security knowledge, vulnerability data, and automation pipelines, a combination he credited with bringing Tulongfeng up to a standard he considers equivalent to Mythos for practical security work.

He drew a vivid contrast between the two approaches. "If the US route is to cultivate a genius hacker, 360's route is to organise a professional attack-and-defence team," Zhou said. The framing reflects a deliberate strategic bet: that deep domain specialization and orchestration can compensate for a raw-capability deficit in foundation models.

The Export-Backdrop

The launch lands against a turbulent policy backdrop in Washington. The Trump administration ordered Anthropic to take its two most powerful models, Mythos and the more restricted Fable 5, offline for all users after citing a potential jailbreak vulnerability, forcing the company to pull access for customers and employees alike. The administration has since sought to resolve the dispute and partially lifted restrictions on Mythos, clearing a controlled re-release to vetted US organizations, even as broader export controls remain in place.

For international customers suddenly cut off from the American model, the vacuum is an opportunity. 360's announcement echoes a broader pattern in which Asian AI firms are moving to fill the space created by the ban. Tokyo-based Sakana AI launched its own Fugu model during the same window, marketing it as delivering frontier capability without the risk of export controls, though the two companies emphasize very different strategies.

Zhou Hongyi's standing adds weight to 360's move. Beyond founding the company, which he built from consumer antivirus products into a widely recognized cybersecurity brand serving enterprises and government clients, he holds a seat on China's top political advisory body. That position gives him direct influence in debates over how the country develops and deploys AI for national security.

Why It Matters

The 360 launch crystallizes a dynamic that the export ban has accelerated rather than contained. By restricting access to its most advanced security AI, the United States may be ceding commercial ground to rivals who are racing to build substitutes, some of which are openly framed as geopolitical counterweights rather than neutral products.

It also raises uncomfortable questions for policymakers. An AI system that can autonomously discover software vulnerabilities is inherently dual-use, valuable for defending critical infrastructure and dangerous in offensive hands. As more countries and companies build comparable tools, the guardrails around who can deploy them, and for what purpose, are being set in a fragmented and largely uncoordinated way.

For the security community, the emergence of a credible Chinese rival to Mythos is a reminder that the capability is diffusing faster than the rules to govern it. Whether 360's tools truly match Mythos in independent testing remains an open question, but the strategic signal is clear: the race to build AI for cybersecurity is now global, and the export controls designed to preserve an American edge may be reshaping the competitive map in ways their architects did not fully intend.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →