Multiple reports, citing sources familiar with the matter, say the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s “Mythos” AI model to audit or scan U.S. government code repositories for security flaws. The activity is reportedly led by CISA’s Attack Surface Evaluation team, a unit described as responsible for digital defense assessments and simulated hacking exercises across government systems.

According to the sources, the scanning aims to identify bugs or weaknesses that could be exploited by foreign spies or cybercriminals. Several outlets report that the audits have already found “numerous” vulnerabilities, though the sources do not provide details on the specific issues discovered or their severity. One report also says Reuters could not determine how much government code the team had reviewed or what the vulnerabilities entailed.

The reports focus primarily on the use of Mythos and the role of CISA’s Attack Surface Evaluation team, with limited information about scope, technical configuration, or documentation of findings.