- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,366
An AI agent has found nearly 1,000 bugs in software used worldwide.

Chinese company 360 Digital Security Group announced it has turned artificial intelligence into a tool for mass vulnerability scanning, Bloomberg reports . The company's system has already found nearly 1,000 previously unknown bugs in popular software, including Microsoft Office and OpenClaw, an open-source framework for creating and running AI agents.
The development is described in a report by Natto Thoughts , a research group studying Chinese cybersecurity. According to the authors, 360 Digital Security Group has in recent months reported on the Vulnerability Discovery Agent, an AI-powered tool for automated vulnerability scanning. The company claims the system has identified nearly 1,000 previously unknown software flaws.
The Beijing-based company previously reported creating AI tools that accelerate bug hunting and exploit chain assembly. These chains allow attackers to sequentially exploit multiple weaknesses and gain access to target computers.
360's development is reminiscent of Mythos , Anthropic's new AI model for autonomously finding and exploiting vulnerabilities in popular technologies. Anthropic claims Mythos is so powerful that only select organizations have been granted access to the model . The company proposes using Mythos to find and patch vulnerabilities before attackers can find them. US authorities are also working to provide federal agencies with access to a version of Mythos.
360 stated that the role of AI within the company has evolved "from a supporting tool to the primary engine of vulnerability discovery." The report's author, Eugenio Benincasa, a senior researcher at the ETH Zurich Center for Security Research, believes that 360 is essentially attempting to fill the same niche as Anthropic with Mythos.
According to Benincasa, even the Chinese company's exaggerated claims demonstrate the development of its core capabilities. The researcher believes that AI is gradually moving away from being a helper and toward becoming a scalable vulnerability detection mechanism, and 360 is well-positioned to promote such developments in China.
A separate risk, according to Benincasa, is related to the Chinese government's control over the cybersecurity industry. Chinese researchers are required to report discovered vulnerabilities to government agencies, and intelligence agencies can use this information for cyber operations. Benincasa believes that close ties between private companies and government agencies can more quickly transform successful vulnerability discovery into offensive tools.
In March, researchers discovered that the 360 Security Claw installer left a private SSL key on devices, identical for all users. This flaw allowed for the interception of encrypted traffic and the execution of man-in-the-middle attacks if an attacker gained access to the victim's network.
In April, Anthropic opened limited access to Claude Mythos Preview , a model for autonomously finding and exploiting vulnerabilities. The company stated that the system is intended to help defenders find dangerous vulnerabilities before attackers.

Chinese company 360 Digital Security Group announced it has turned artificial intelligence into a tool for mass vulnerability scanning, Bloomberg reports . The company's system has already found nearly 1,000 previously unknown bugs in popular software, including Microsoft Office and OpenClaw, an open-source framework for creating and running AI agents.
The development is described in a report by Natto Thoughts , a research group studying Chinese cybersecurity. According to the authors, 360 Digital Security Group has in recent months reported on the Vulnerability Discovery Agent, an AI-powered tool for automated vulnerability scanning. The company claims the system has identified nearly 1,000 previously unknown software flaws.
The Beijing-based company previously reported creating AI tools that accelerate bug hunting and exploit chain assembly. These chains allow attackers to sequentially exploit multiple weaknesses and gain access to target computers.
360's development is reminiscent of Mythos , Anthropic's new AI model for autonomously finding and exploiting vulnerabilities in popular technologies. Anthropic claims Mythos is so powerful that only select organizations have been granted access to the model . The company proposes using Mythos to find and patch vulnerabilities before attackers can find them. US authorities are also working to provide federal agencies with access to a version of Mythos.
360 stated that the role of AI within the company has evolved "from a supporting tool to the primary engine of vulnerability discovery." The report's author, Eugenio Benincasa, a senior researcher at the ETH Zurich Center for Security Research, believes that 360 is essentially attempting to fill the same niche as Anthropic with Mythos.
According to Benincasa, even the Chinese company's exaggerated claims demonstrate the development of its core capabilities. The researcher believes that AI is gradually moving away from being a helper and toward becoming a scalable vulnerability detection mechanism, and 360 is well-positioned to promote such developments in China.
A separate risk, according to Benincasa, is related to the Chinese government's control over the cybersecurity industry. Chinese researchers are required to report discovered vulnerabilities to government agencies, and intelligence agencies can use this information for cyber operations. Benincasa believes that close ties between private companies and government agencies can more quickly transform successful vulnerability discovery into offensive tools.
In March, researchers discovered that the 360 Security Claw installer left a private SSL key on devices, identical for all users. This flaw allowed for the interception of encrypted traffic and the execution of man-in-the-middle attacks if an attacker gained access to the victim's network.
In April, Anthropic opened limited access to Claude Mythos Preview , a model for autonomously finding and exploiting vulnerabilities. The company stated that the system is intended to help defenders find dangerous vulnerabilities before attackers.