CISA lacks access to Anthropic's Mythos Preview cybersecurity model while NSA and Commerce use it
The Cybersecurity and Infrastructure Security Agency (CISA) has not received access to Anthropic's Mythos Preview model, according to an Axios report, while the NSA and Commerce Department are using the AI tool to find security vulnerabilities. The exclusion raises questions about the agency's ability to fulfill its role as the nation's central cybersecurity coordinator.
The Cybersecurity and Infrastructure Security Agency (CISA) has not received access to Anthropic's Mythos Preview model, according to an Axios report, while the National Security Agency and Commerce Department are using the AI tool to find security vulnerabilities.
According to Anthropic, Mythos Preview has identified security issues "in every major operating system and web browser." The company is providing restricted access to give key institutions a "head start" on cyber defenses, according to Newton Cheng, Anthropic's frontier red team cyber lead.
CISA serves as the central coordinating body for cybersecurity information in the United States, helping state and local officials running elections and public utilities respond to vulnerabilities and attacks. The agency is part of the Department of Homeland Security.
Anthhropic stated in a blog post that it has "been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities." An unnamed Anthropic official told Axios that CISA was among the agencies briefed on the model. The Trump administration has been negotiating broader access to the tool across federal agencies.
Anthhropic declined to comment on CISA's access status. CISA did not immediately respond to a request for comment.
CISA under pressure
The reported exclusion comes as CISA faces resource constraints and political pressure. The agency lost staff during the Department of Government Efficiency's cost-cutting efforts, with additional personnel reassigned to immigration priorities under DHS.
CISA's acting director told Congress that the agency's resources to detect hacks were limited during the current DHS shutdown. The Trump administration is seeking to cut hundreds of millions of dollars from CISA's budget.
The agency has been a target of political attacks from the Trump administration and congressional Republicans, particularly after CISA declared the 2020 election "the most secure in American history." Trump fired the official who led the agency in his first administration.
What this means
The exclusion of the nation's primary cybersecurity coordination agency from a tool designed to find critical vulnerabilities represents a significant gap in defensive capabilities. While other federal agencies test Mythos Preview's ability to identify security flaws in major operating systems and browsers, CISA—the agency responsible for coordinating threat information to state and local governments running critical infrastructure—remains on the sidelines. This creates a potential information asymmetry where the central coordinating body lacks access to the same defensive tools available to other federal entities, potentially hampering its ability to fulfill its core mission.
Related Articles
Anthropic Python SDK v0.106.0 marks Claude Opus 4.1 as deprecated
Anthropic released version 0.106.0 of its Python SDK on June 5, 2026, marking Claude Opus 4.1 as deprecated. The update also includes bug fixes for Foundry client methods and schema transformation handling.
Google Gemini app adds Contacts integration to find, edit, and delete contact information
Google is rolling out a new Contacts integration for the Gemini app. The feature, available in Personal Intelligence > Connected Apps, allows Gemini to find, add, edit, or delete contacts through natural language prompts.
OpenAI launches Lockdown Mode to block prompt injection data exfiltration attacks
OpenAI has released Lockdown Mode, an optional security setting that protects against prompt injection attacks by limiting network requests and image fetching in ChatGPT. The feature is designed for users handling sensitive data and disables some ChatGPT capabilities including Deep Research and Agent Mode.
Cline v3.88.0 Adds Fireworks AI Kimi K2.6 as Default Model, Fixes MCP Server Management
Cline, the AI coding assistant, released v3.88.0 on June 5, 2025, switching its default Fireworks AI model to Kimi K2.6. The update fixes critical MCP server management bugs and enables the upstream recommended models endpoint for all users.
Comments
Loading...