{"id":398677,"date":"2026-06-30T05:55:08","date_gmt":"2026-06-30T05:55:08","guid":{"rendered":"https:\/\/bizscoreai.com\/blog\/?p=398677"},"modified":"2026-06-30T05:55:08","modified_gmt":"2026-06-30T05:55:08","slug":"qihoo-360-tulongfeng-3432-vulnerabilities","status":"publish","type":"post","link":"https:\/\/bizscoreai.com\/blog\/qihoo-360-tulongfeng-3432-vulnerabilities\/","title":{"rendered":"Qihoo 360&#8217;s Tulongfeng: 3,432 Vulns Found, AI Sovereignty Debate Heats Up"},"content":{"rendered":"\n<p class=\"post-meta-row\"><span class=\"post-meta-time\">\u23f1 5 min read<\/span> \u00b7 <span class=\"post-meta-updated\">Last updated 2026-06-30<\/span><\/p>\n<nav class=\"post-toc\" aria-label=\"Table of contents\"><strong>In this article<\/strong><ol><li><a href=\"#why-it-matters\">Why It Matters<\/a><\/li><li><a href=\"#whats-new-how-it-works\">What&#8217;s New \/ How It Works<\/a><\/li><li><a href=\"#the-numbers\">The Numbers<\/a><\/li><li><a href=\"#what-comes-next\">What Comes Next<\/a><\/li><li><a href=\"#what-this-means-for-you\">What This Means for You<\/a><\/li><li><a href=\"#the-bigger-picture\">The Bigger Picture<\/a><\/li><\/ol><\/nav>\n\n\n\n<p class=\"wp-block-paragraph\">Qihoo 360, a Beijing-based cybersecurity firm on the U.S. Entity List, has unveiled two homegrown AI tools designed to compete with Anthropic&#8217;s Mythos vulnerability hunter. The company says its Tulongfeng platform has already flagged 3,432 software vulnerabilities, while its Yitianzhen system automates cyber defense. CEO Hongyi Zhou framed the effort as a necessity for digital sovereignty, comparing advanced bug-finding AI to nuclear weapons.<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote class=\"pull-quote\"><p>Vulnerability-hunting AI has become a cyber nuclear weapon: no nation can afford to be the only one without it.<\/p><\/blockquote><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-it-matters\">Why It Matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AI-powered vulnerability discovery is reshaping cybersecurity. Anthropic&#8217;s Mythos has found tens of thousands of flaws across open-source code, raising alarms about catastrophic risk and geopolitical control. The emergence of a Chinese counterpart intensifies the debate, echoing Cold War deterrence logic. Qihoo 360&#8217;s placement on the <a href=\"https:\/\/www.ecfr.gov\/current\/title-15\/subtitle-B\/chapter-VII\/subchapter-C\/part-744\/appendix-Supplement%20No.%204%20to%20Part%20744\" rel=\"noopener\" target=\"_blank\">U.S. Entity List<\/a> in 2020 for <strong>enabling China&#8217;s high-technology surveillance<\/strong> underscores the delicate intersection of national security, AI, and international trust.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"whats-new-how-it-works\">What&#8217;s New \/ How It Works<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Rather than a single frontier model, Tulongfeng is an orchestrated vulnerability-research platform built on an agent-based approach. It pairs AI models with security expertise and automated tools, an architecture Zhou says is designed to compensate for a 20-30% capability gap between domestic Chinese models and the top Western ones. Yitianzhen operates as an AI-driven security operations center (SOC) layer for automated defense. The names draw from a classic martial arts novel: Tulongfeng translates to the tip of the dragon saber, while Yitianzhen refers to a cluster sword formation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zhou framed the technical contest in stark Cold War terms. He argued that the U.S. could use Mythos to scan Chinese systems while China remains blind, creating a dangerous asymmetry. The export ban on Anthropic&#8217;s Fable 5, which he called the &#8220;civilian, neutered version of Mythos,&#8221; proved, in his view, that Washington considers vulnerability-hunting AI a strategic asset that must be kept exclusively in American hands.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-numbers\">The Numbers<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>3,432<\/strong> vulnerabilities flagged by Tulongfeng across open-source code, binary software, and AI\/agentic systems, according to Qihoo 360&#8217;s CEO.<\/li>\n<li><strong>250,000<\/strong> vulnerabilities in Qihoo 360&#8217;s internal database accumulated since 2005, used to train the tool.<\/li>\n<li><strong>20-30%<\/strong> estimated gap in underlying AI model capabilities between China\u2019s best models and those from the U.S., per Zhou.<\/li>\n<li><strong>23,000+<\/strong> total findings generated by Anthropic&#8217;s Claude Mythos Preview across more than 1,000 open-source projects, including over <strong>6,200<\/strong> rated high or critical.<\/li>\n<li><strong>10,000+<\/strong> serious flaws identified to date by Project Glasswing partners (Cisco, Palo Alto Networks) using Mythos&#8217; full capabilities.<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>The same logic that kept nuclear powers from direct war now applies to cybersecurity: mutual deterrence through advanced AI capabilities.<\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-comes-next\">What Comes Next<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The AI sovereignty fire is gaining fuel. The U.S. government partially rescinded the Mythos 5 export ban, granting access to a select group of more than 100 companies and agencies, while Fable 5 remains blocked. Security analyst Laura Wilber of Enea said the move added yet more fuel to the digital sovereignty push in Europe, likely channeling more funding to Mistral. Separately, Tsinghua University professor Jie Tang, founder of Z.ai, predicted a Chinese &#8220;Mythos&#8221; class model would arrive before Q1 2027. The arms race in vulnerability-hunting AI shows no sign of cooling.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-this-means-for-you\">What This Means for You<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For businesses that rely on digital infrastructure, automated vulnerability discovery at scale changes the threat landscape. Tools like Mythos and Tulongfeng promise faster patching but also lower the barrier for identifying exploitable weaknesses. Staying informed about these capabilities is becoming part of basic cybersecurity hygiene. As we have covered recently, the rapid progress in AI-driven bug hunting means that every organization&#8217;s attack surface is under more intense scrutiny. Catch up with <a href=\"https:\/\/bizscoreai.com\/blog\/z-ai-glm-52-mythos-cybersecurity\/\">Z.ai GLM-5.2 matching Mythos in cybersecurity<\/a> and <a href=\"https:\/\/bizscoreai.com\/blog\/gpt-5-6-sol-limited-preview\/\">OpenAI&#8217;s GPT-5.6 Sol cyber safeguards<\/a> to see how the defensive and offensive capabilities of AI are evolving together.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-bigger-picture\">The Bigger Picture<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Qihoo 360 announcement is more than a product launch; it&#8217;s a signal that the AI security race is now fully multipolar, with cyber-deterrence doctrines being openly adopted. Whether Tulongfeng lives up to its claims or not, the rhetorical framing makes clear that nations see vulnerability-hunting AI as a strategic asset. The debate over sovereignty and export controls will shape the next generation of internet security for everyone.<\/p>\n\n\n\n<h2 id=\"faq\">Frequently Asked Questions<\/h2><div class=\"post-faq\"><details class=\"faq-item\"><summary>What is Tulongfeng and how does it compare to Anthropic&#8217;s Mythos?<\/summary><div class=\"faq-answer\">Tulongfeng is Qihoo 360&#8217;s AI-driven vulnerability hunting platform that uses an agent-based orchestration approach rather than a single frontier model. It claimed to have found 3,432 vulnerabilities by pairing AI models with security expertise. Anthropic&#8217;s Mythos Preview generated over 23,000 findings across 1,000+ open-source projects, with partners in Project Glasswing finding more than 10,000 serious flaws. Qihoo 360 argues its architecture compensates for a 20-30% gap in underlying model capabilities between Chinese and U.S. systems.<\/div><\/details><details class=\"faq-item\"><summary>Why is Qihoo 360 on the U.S. Entity List?<\/summary><div class=\"faq-answer\">Qihoo 360 was added to the Bureau of Industry and Security&#8217;s Entity List in 2020 after being accused of enabling China&#8217;s high-technology surveillance in the alleged crackdown on Uyghurs in Xinjiang. This listing restricts its access to U.S. exports, making the development of indigenous AI tools like Tulongfeng both a technical and geopolitical statement.<\/div><\/details><details class=\"faq-item\"><summary>What does the &#8216;cyber nuclear deterrence&#8217; framing mean?<\/summary><div class=\"faq-answer\">Qihoo 360 CEO Hongyi Zhou compared advanced vulnerability-hunting AI to nuclear weapons, arguing that when both sides possess such capabilities, mutual deterrence prevents aggressive use. He suggested that the U.S. could use Mythos to scan Chinese systems while China remains blind, and that a similar Chinese capability is needed to shift the balance and avoid one-sided transparency.<\/div><\/details><details class=\"faq-item\"><summary>How many vulnerabilities has Mythos found versus Tulongfeng?<\/summary><div class=\"faq-answer\">According to respective company claims, Tulongfeng flagged 3,432 vulnerabilities across open-source, binary, and AI\/agentic systems, trained on Qihoo 360&#8217;s 250,000-vulnerability database. Anthropic&#8217;s Claude Mythos Preview found over 23,000 findings across more than 1,000 open-source projects, with over 6,200 estimated as high or critical. Its Project Glasswing partners have identified more than 10,000 serious flaws to date.<\/div><\/details><details class=\"faq-item\"><summary>What is Project Glasswing?<\/summary><div class=\"faq-answer\">Project Glasswing is the taskforce of security partners, including Cisco and Palo Alto Networks, that has exclusive access to the full capabilities of Anthropic&#8217;s Mythos. It was launched to use the model for defensive vulnerability discovery at scale and to coordinate responsible disclosure of critical findings.<\/div><\/details><details class=\"faq-item\"><summary>Will a Chinese Mythos-class model really arrive by 2027?<\/summary><div class=\"faq-answer\">Tsinghua University professor Jie Tang, founder of Z.ai, estimated that a Chinese &#8220;Mythos&#8221; class model would arrive before Q1 2027. His organization recently shipped the well-received GLM-5.2 open-weight model, which has already shown competitive cybersecurity bug-finding performance, narrowing the gap with proprietary Western systems.<\/div><\/details><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Qihoo 360 unveils Tulongfeng AI vulnerability hunter claiming 3,432 flaws; Zhou frames it as cyber nuclear deterrence, fueling AI sovereignty debate.<\/p>\n","protected":false},"author":1,"featured_media":398680,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"","rank_math_description":"Qihoo 360 unveils Tulongfeng AI vulnerability hunter claiming 3,432 flaws; Zhou frames it as cyber nuclear deterrence, fueling AI sovereignty debate.","rank_math_focus_keyword":"360 Tulongfeng","footnotes":""},"categories":[1],"tags":[25145,24912,25248,25262,25255,25260,25261,25263],"class_list":["post-398677","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","tag-ai-security","tag-anthropic","tag-cybersecurity","tag-digital-sovereignty","tag-mythos","tag-qihoo-360","tag-tulongfeng","tag-vulnerability-hunting"],"elementor_data":null,"elementor_edit_mode":null,"_links":{"self":[{"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/posts\/398677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/comments?post=398677"}],"version-history":[{"count":1,"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/posts\/398677\/revisions"}],"predecessor-version":[{"id":398679,"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/posts\/398677\/revisions\/398679"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/media\/398680"}],"wp:attachment":[{"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/media?parent=398677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/categories?post=398677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bizscoreai.com\/blog\/wp-json\/wp\/v2\/tags?post=398677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}