{"id":972,"date":"2026-06-30T05:55:10","date_gmt":"2026-06-30T05:55:10","guid":{"rendered":"https:\/\/feedsta.ai\/blog\/?p=972"},"modified":"2026-07-19T06:46:18","modified_gmt":"2026-07-19T06:46:18","slug":"qihoo-360-tulongfeng-3432-vulnerabilities-ai-deterrence","status":"publish","type":"post","link":"https:\/\/feedsta.ai\/blog\/qihoo-360-tulongfeng-3432-vulnerabilities-ai-deterrence\/","title":{"rendered":"360&#8217;s Tulongfeng Finds 3,432 Security Bugs as AI Sovereignty Heats Up"},"content":{"rendered":"\n<p class=\"post-meta-row\"><span class=\"post-meta-time\">\u23f1 7 min read<\/span> \u00b7 <span class=\"post-meta-updated\">Last updated 2026-06-30<\/span><\/p>\n<nav class=\"post-toc\" aria-label=\"Table of contents\"><strong>In this article<\/strong><ol><li><a href=\"#why-it-matters\">Why It Matters<\/a><\/li><li><a href=\"#whats-new\">What&#8217;s New<\/a><\/li><li><a href=\"#the-numbers\">The Numbers<\/a><\/li><li><a href=\"#what-comes-next\">What Comes Next<\/a><\/li><li><a href=\"#what-this-means-for-you\">What This Means for You<\/a><\/li><li><a href=\"#the-bigger-picture\">The Bigger Picture<\/a><\/li><li><a href=\"#faq\">FAQ<\/a><\/li><\/ol><\/nav>\n\n\n\n<p class=\"wp-block-paragraph\">Qihoo 360 Security Technology has unveiled an AI tool called Tulongfeng that it claims has automatically flagged 3,432 software vulnerabilities across open-source code, binary software, and AI systems. Founder and CEO Hongyi Zhou framed the platform as a strategic deterrent to Anthropic&#8217;s Mythos model, drawing an explicit parallel to nuclear mutual deterrence. The Beijing-based firm, placed on the U.S. Entity List in 2020, released the tool at the ISC.AI 2026 conference alongside a companion defense system called Yitianzhen.<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote class=\"pull-quote\"><p>Owning the strongest bug-hunting AI is no longer about patching holes; it&#8217;s about strategic deterrence in a cyber arms race.<\/p><\/blockquote><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-it-matters\">Why It Matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Automated vulnerability hunting has accelerated rapidly since Anthropic introduced its Mythos model. Through its Claude Mythos Preview, Anthropic claimed the system generated over 23,000 findings across more than 1,000 open-source projects, including an estimated 6,200 that were classed as high or critical. Under <a href=\"https:\/\/www.sdxcentral.com\/news\/anthropic-bug-hunter-launched-with-all-star-cast-and-good-old-us-patriotism\/\" rel=\"noopener\" target=\"_blank\">Project Glasswing<\/a>, the taskforce with exclusive use of Mythos&#8217; full capabilities, partners including Cisco and Palo Alto Networks have identified more than 10,000 serious flaws to date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Qihoo 360&#8217;s response shows that the battle for AI-driven vulnerability discovery is now explicitly geopolitical. The company, placed on the <a href=\"https:\/\/www.ecfr.gov\/current\/title-15\/subtitle-B\/chapter-VII\/subchapter-C\/part-744\/appendix-Supplement%20No.%204%20to%20Part%20744\" rel=\"noopener\" target=\"_blank\">Bureau of Industry and Security&#8217;s Entity List<\/a> in 2020 after being accused of enabling high-technology surveillance, is framing its tools as a necessity for strategic balance. Zhou characterized Mythos as relying on &#8220;the strongest model, the strongest computing power and the strongest chips,&#8221; while China, he argues, must build fully sovereign alternatives to avoid falling behind in a one-sided transparency game.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"whats-new\">What&#8217;s New in Tulongfeng<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Tulongfeng is not just another standalone model; Zhou describes it as an orchestrated vulnerability-research platform built with a software-first, AI agent-driven approach. It was trained on 360&#8217;s database of 250,000 vulnerabilities accumulated since the company&#8217;s inception in 2005. The system works opposite a companion defense model, Yitianzhen, which automates cyber-defense as an AI-driven security operations center layer. Both were released under the product banner &#8220;Yitian Tulong,&#8221; referencing the classic martial arts novel &#8220;Heavenly Sword and Dragon Saber.&#8221; Tulongfeng translates as the tip of the dragon saber, while Yitianzhen refers to a clustered sword formation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zhou claims Chinese AI models lag behind U.S. frontrunners by 20 to 30 percent in underlying capabilities, making the agent-coordination approach a practical workaround. At the same time, Tsinghua University professor Jie Tang, founder of Z.ai, estimated a Chinese &#8220;Mythos&#8221; class model could arrive before the first quarter of 2027, suggesting the capability gap may close faster than expected if the right investment materializes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The announcement landed in a tense moment. Anthropic recently <a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cwyklykn5dwo\" rel=\"noopener\" target=\"_blank\">accused Chinese tech giant Alibaba<\/a> of extracting capabilities from its Claude models. Meanwhile, the U.S. government temporarily banned exports of Anthropic&#8217;s Mythos 5 and Fable 5 models, partially rescinding the ban for Mythos 5 for a select group of 100-plus companies and agencies, while Fable 5 remains blocked. Security expert Laura Wilber, senior analyst at Enea, argued the export ban added yet more fuel to the digital sovereignty fire in Europe, predicting more funding would flow to the EU&#8217;s leading homegrown large language model, Mistral.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-numbers\">The Numbers Behind the Arms Race<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>3,432<\/strong> software vulnerabilities flagged by Tulongfeng across open-source, binary, and agentic systems, according to Zhou.<\/li>\n<li><strong>250,000<\/strong> vulnerabilities used to train Tulongfeng, drawn from Qihoo 360&#8217;s database since 2005.<\/li>\n<li><strong>23,000+<\/strong> total findings Anthropic&#8217;s Claude Mythos Preview generated across more than 1,000 open-source projects, including <strong>6,200+<\/strong> estimated as high or critical.<\/li>\n<li><strong>10,000+<\/strong> serious flaws identified to date by Project Glasswing partners with exclusive Mythos access.<\/li>\n<li><strong>20-30%<\/strong> estimated performance gap between top Chinese AI models and the most capable Western models, per Zhou.<\/li>\n<li><strong>100+<\/strong> companies and agencies granted access to Mythos 5 after the partial export ban lift.<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>&quot;Why has nuclear war never actually broken out? Because everyone possesses nuclear weapons, allowing for mutual deterrence. The same applies to cybersecurity. If others have them, so do I; I won&#8217;t be passively attacked.&quot;, Hongyi Zhou, founder and CEO, Qihoo 360<\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-comes-next\">What Comes Next for AI Bug Hunting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The immediate future looks like an intensifying arms race in AI cybersecurity tools. While Qihoo 360&#8217;s claims have not been independently verified, the tone is already influencing policy and investment. In Europe, the push for digital sovereignty will likely accelerate Mistral&#8217;s role as a homegrown counterweight, while in China, the push toward a fully indigenous Mythos equivalent could make the first quarter of 2027 a key milestone to watch. The U.S. will continue to calibrate export controls, but the timing of Tulongfeng&#8217;s release, the Alibaba extraction accusations, and new model announcements suggest each side will keep one-upping the other in both capability and rhetoric.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-this-means-for-you\">What This Means for Security Teams<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Automated bug-hunting AI cuts both ways. In defenders&#8217; hands, tools like Mythos and Tulongfeng can find and fix flaws faster than human researchers ever could, hardening the open-source libraries that almost every application depends on. In attackers&#8217; hands, the same capability shrinks the window between a vulnerability being discovered and being exploited. For any organization that ships or relies on software, that raises the premium on patching quickly and tracking which AI-discovered flaws affect the components in their stack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also reframes the open-source supply chain as strategic terrain. When a single bug-hunting platform can scan thousands of projects at once, the findings it surfaces, and who gets to see them first, become a matter of national policy as much as engineering. Expect more software vendors, cloud providers, and governments to treat coordinated vulnerability disclosure and the provenance of their dependencies as security priorities rather than afterthoughts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For deeper context on how Chinese AI models are already matching Western benchmarks, read our article on <a href=\"https:\/\/feedsta.ai\/blog\/china-glm-5-2-open-weight-mythos-cybersecurity\/\" rel=\"noopener\">China&#8217;s open-weight GLM-5.2 model matching Mythos in cybersecurity bug finding<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-bigger-picture\">The Bigger Picture on AI Sovereignty<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When vulnerability discovery becomes a national strategic asset, the stakes for every connected application rise. The debate over AI sovereignty is no longer a distant policy discussion; it is reshaping which tools get trusted, which stay secure, and how quickly vulnerabilities get patched. Whether framed as a dragon saber or a sword formation, automated bug hunting has become a geopolitical instrument, and the contest between the U.S., China, and Europe over who builds the strongest one is only beginning.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"faq\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What is Qihoo 360&#8217;s Tulongfeng and how many bugs has it found?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Tulongfeng is an AI vulnerability-hunting platform built by Chinese cybersecurity firm Qihoo 360, unveiled at ISC.AI 2026. Founder Hongyi Zhou stated that the system has automatically flagged 3,432 software vulnerabilities across open-source code, binary software, and AI systems, and was trained on 360&#8217;s database of 250,000 vulnerabilities accumulated since 2005. The figures have not been independently verified.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How does Tulongfeng compare to Anthropic&#8217;s Mythos?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic&#8217;s Claude Mythos Preview generated over 23,000 findings across more than 1,000 open-source projects, including 6,200+ estimated as high or critical, and Project Glasswing partners using full Mythos capabilities have identified 10,000+ serious flaws. Qihoo 360 claims 3,432 findings from Tulongfeng so far. Zhou argues Tulongfeng&#8217;s agent-driven approach is better suited to Chinese AI models, which he says trail top U.S. models by 20 to 30 percent. Independent head-to-head benchmarks are not yet available.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why does Qihoo 360 frame AI vulnerability hunting as nuclear deterrence?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Zhou explicitly compared Mythos to nuclear weapons, stating: &quot;Why has nuclear war never actually broken out? Because everyone possesses nuclear weapons, allowing for mutual deterrence. The same applies to cybersecurity. If others have them, so do I; I won&#8217;t be passively attacked.&quot; His argument is that if only one side possesses an automated vulnerability weapon, the other becomes blind to threats, so China must build an equivalent strategic deterrent. Qihoo 360 was placed on the U.S. Entity List in 2020 after being accused of enabling high-technology surveillance.<\/p>\n\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"headline\":\"360's Tulongfeng Finds 3,432 Security Bugs as AI Sovereignty Heats Up\",\"description\":\"Qihoo 360 says its Tulongfeng AI has flagged 3,432 vulnerabilities, framing AI bug-hunting as strategic deterrence against Anthropic's Mythos.\",\"datePublished\":\"2026-07-19T06:46:17.077Z\",\"publisher\":{\"@type\":\"Organization\",\"name\":\"Feedsta\"}},{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is Qihoo 360's Tulongfeng and how many bugs has it found?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Tulongfeng is an AI vulnerability-hunting platform built by Chinese cybersecurity firm Qihoo 360, unveiled at ISC.AI 2026. Founder Hongyi Zhou stated that the system has automatically flagged 3,432 software vulnerabilities across open-source code, binary software, and AI systems, and was trained on 360's database of 250,000 vulnerabilities accumulated since 2005. The figures have not been independently verified.\"}},{\"@type\":\"Question\",\"name\":\"How does Tulongfeng compare to Anthropic's Mythos?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Anthropic's Claude Mythos Preview generated over 23,000 findings across more than 1,000 open-source projects, including 6,200+ estimated as high or critical, and Project Glasswing partners using full Mythos capabilities have identified 10,000+ serious flaws. Qihoo 360 claims 3,432 findings from Tulongfeng so far. Zhou argues Tulongfeng's agent-driven approach is better suited to Chinese AI models, which he says trail top U.S. models by 20 to 30 percent. Independent head-to-head benchmarks are not yet available.\"}},{\"@type\":\"Question\",\"name\":\"Why does Qihoo 360 frame AI vulnerability hunting as nuclear deterrence?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Zhou explicitly compared Mythos to nuclear weapons, stating: \\\"Why has nuclear war never actually broken out? Because everyone possesses nuclear weapons, allowing for mutual deterrence. The same applies to cybersecurity. If others have them, so do I; I won't be passively attacked.\\\" His argument is that if only one side possesses an automated vulnerability weapon, the other becomes blind to threats, so China must build an equivalent strategic deterrent. Qihoo 360 was placed on the U.S. Entity List in 2020 after being accused of enabling high-technology surveillance.\"}}]}]}<\/script>","protected":false},"excerpt":{"rendered":"<p>Qihoo 360 says its Tulongfeng AI has flagged 3,432 vulnerabilities, framing AI bug-hunting as strategic deterrence against Anthropic&#8217;s Mythos.<\/p>\n","protected":false},"author":1,"featured_media":973,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","rank_math_canonical_url":"","rank_math_facebook_title":"","rank_math_facebook_description":"","rank_math_twitter_title":"","rank_math_twitter_description":"","rank_math_robots":[],"footnotes":""},"categories":[400,1],"tags":[580,579,62,570,575,578,471,577],"class_list":["post-972","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-ai-news","tag-ai-sovereignty","tag-ai-vulnerability","tag-anthropic","tag-cybersecurity","tag-mythos","tag-qihoo-360","tag-social-media-security","tag-tulongfeng"],"_links":{"self":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts\/972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/comments?post=972"}],"version-history":[{"count":3,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts\/972\/revisions"}],"predecessor-version":[{"id":1369,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/posts\/972\/revisions\/1369"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/media\/973"}],"wp:attachment":[{"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/media?parent=972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/categories?post=972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/feedsta.ai\/blog\/wp-json\/wp\/v2\/tags?post=972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}