360’s Zhou Hongyi Unveils ‘Heavenly Sword and Dragon Saber’ AI Security Duo to Counter Anthropic’s Mythos
At ISC.AI 2026, 360 founder Zhou Hongyi launched two core AI-driven security systems—Tulongfeng for automated vulnerability hunting and Yitianzhen for autonomous defense—positioning them as China’s answer to Anthropic’s restricted Mythos model. The release marks a strategic shift toward agent-based cyber defense amid rising fears of AI-supercharged threats.
BEIJING, June 24, 2026 — At the opening of the ISC.AI 2026 conference, 360 Group founder Zhou Hongyi officially unveiled the company’s two-pronged AI security arsenal, code-named “Heavenly Sword and Dragon Saber.” The dual system—vulnerability-hunting agent Tulongfeng and automated defense system Yitianzhen—is designed to match the capabilities of Anthropic’s Mythos, which the U.S. government recently blocked from foreign access over national security concerns.
Zhou framed the launch as a direct response to the paradigm shift triggered by Mythos, a model that can autonomously discover, analyze, and weaponize software vulnerabilities. “Mythos is not just a smarter chatbot. It is a cyber nuclear weapon of the AI era,” he said. The model’s ability to slash vulnerability discovery time by a factor of 100, slash costs by 1,000 times, and generate exploit code at scale has redrawn the threat landscape. Its leak earlier sent U.S. cybersecurity stocks tumbling and prompted the White House to restrict the model even from Anthropic’s own non-U.S. employees.
Zhou warned that without a comparable indigenous capability, China faces a “second one-way transparency” in cyberspace—shifting from “the enemy hides, we are visible” to “the enemy is faster, and we are outnumbered.” He predicted a surge in attacks on critical infrastructure and key industries over the next few years.
Rather than replicate the brute-force compute approach of Mythos, 360 is leveraging an agent-based architecture that blends large-model intelligence with decades of real-world attack data, security expert heuristics, and a multi-agent swarm design. Zhou described this as China’s “engineering strength” route. Tulongfeng has already unearthed 3,432 vulnerabilities—105 confirmed by regulators, many classified as high-risk by the national vulnerability database—spanning open-source code, Windows kernel flaws, Office RCE (remote code execution) bugs, and AI agent platforms. Zhou claimed Tulongfeng matches Mythos in core capability.
The companion system, Yitianzhen, extends automation from hunting to defense. It autonomously plans tasks, analyzes alerts, triggers incident response, and learns from every encounter, moving security operations from manual monitoring toward an “autopilot” mode. “The only way forward is to pit computing power against computing power,” Zhou said. “We must shift from a human-wave defense to autonomous driving.”
To strengthen domestic collaboration, 360 also launched the “Stone Shield” (Panshi Zhi Dun) initiative, bringing together chipmakers like Phytium, operating system vendors like Kylin, and cloud and database partners. The group will receive early access to the two AI security systems, creating a trusted ecosystem to protect China’s critical infrastructure before threats materialize.
“The AI security race has just begun,” Zhou concluded. “China is not absent, and it must not be absent.”