Qihoo 360 Takes On Anthropic With Its Bug-Hunting AI

Qihoo 360

Qihoo 360 has unveiled Tu Long Feng, its bug-hunting AI, and pushes the cybersecurity race to deterrence-level stakes. Founder Zhou Hongyi owns the nuclear comparison and claims 3,432 vulnerabilities already found. Beijing is stepping into an arena where Anthropic was setting the pace.

Key Takeaways

  • Qihoo 360 launches Tu Long Feng (vulnerability hunting) and Yi Tian Zhen (defense automation).
  • Zhou Hongyi frames Mythos as a cyber-nuclear weapon and calls for offensive parity.
  • Tu Long Feng has already identified 3,432 vulnerabilities despite a 20-30% capability gap with Western models.

Have an AI Sum Up This Article

ChatGPT

Beijing makes its move

Qihoo 360, founded by Zhou Hongyi, announced two AI cybersecurity tools at a Beijing conference on June 28. The first, Tu Long Feng, is dedicated to hunting software vulnerabilities. The second, Yi Tian Zhen, automates defense on the enterprise side.

The timing is not random. A few days earlier, the Trump administration reopened access to Claude Mythos for around 100 US operators. Beijing could not leave that signal unanswered, and 360 serves as the industrial flag-bearer.

Tu Long Feng has already identified 3,432 vulnerabilities per 360’s numbers. That is a meaningful volume if the count holds up to an audit. The company has not disclosed severity or its responsible-disclosure channels.

Zhou Hongyi openly acknowledged a technical lag against Western models. The best Chinese LLMs would still trail Anthropic, OpenAI and Google by 20 to 30 percent. The 360 strategy works around that gap by combining the model with human security expertise and automated tooling.

This posture echoes what Anthropic has been pushing for months. Anthropic has banned 832 accounts over AI-enabled cyberattacks in a year and published a mapping alongside MITRE. The American defensive discipline now finds its mirror in a claimed Chinese counterpart.


Qihoo 360

The cyber-nuclear pitch

Zhou Hongyi delivered a metaphor that traveled fast among analysts. Why has there never been a real nuclear war, he asked, except that each side had the weapon and deterred the other. His thesis: AI cybersecurity follows the same logic of mutual deterrence.

He then labeled Claude Mythos’s capabilities a cyber-nuclear weapon of the AI era. The framing sounds like provocation but carries strategic logic. If China cannot match raw efficacy, it can at least declare parity through deterrence.

The nuclear analogy aims at a second audience: regulators and militaries. Zhou wants to push AI cybersecurity into a strategic weapons framework, which would impose treaties and inspections, instead of leaving it on an open market where Anthropic gains ground every quarter.

The pitch raises a real ethical issue. An AI that hunts vulnerabilities can also exploit them. Tu Long Feng and Yi Tian Zhen are presented as defensive, but the same architecture serves any state offensive program. The ambiguity is by design.

Anthropic holds a symmetrical but opposite stance: Mythos is framed as a defensive tool reserved for vetted operators, under US export control. The 360 narrative challenges that moral monopoly and offers a Chinese alternative license for countries aligned with Beijing.


Also on Horizon:


What it means for the AI cyber market

In the short term, Asian cyber buyers now have a credible Chinese alternative. Chinese companies blocked by US export controls on Mythos can test Tu Long Feng and Yi Tian Zhen. Critical infrastructure operators in Singapore, Indonesia or Vietnam will have to pick a side.

Security researchers will scrutinize Tu Long Feng closely. 3,432 announced flaws is a number that demands an audit. If a meaningful share holds up, 360 redefines the bug bounty market and threatens traditional programs like HackerOne or Bugcrowd, where hunting remains human-driven.

In the medium term, the capability race accelerates. Anthropic has to prove its technical lead holds. If 360 stacks operational volume while Mythos stays restricted to Washington-vetted clients, the technical gap could be offset by an experience gap. The field matters as much as the model.

Zhou’s cyber-nuclear rhetoric could also seep into diplomatic chambers. China has pushed for years for an AI treaty. Framing cybersecurity as a weapon of mass destruction is a rhetorical lever for exactly that. Foreign ministries will have to answer this grammar in the coming months.

Finally, the 360 trajectory validates a broader thesis. Chinese players close technical gaps with tooling and vertical integration. That playbook already worked in hardware, EVs and batteries. If it works in AI cybersecurity, the market balance tips on something other than pure model competition.

Follow the story on Horizon.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *