Via freepnglogo.com
Qihoo 360 and Zhipu AI unveiled competing cybersecurity tools as Beijing races to close a capability gap with US firms
Two of China’s most prominent AI companies just made a coordinated statement to the world: the gap between Chinese and American cyber-AI is shrinking, and fast. At the ISC.AI 2026 conference in Beijing on June 24, Qihoo 360 founder Zhou Hongyi unveiled an automated vulnerability-hunting suite while Zhipu AI showed off benchmark results putting its latest model within striking distance of Anthropic’s flagship.
Anthropic launched Claude Mythos 5 on June 9, barely two weeks before Beijing’s conference.
What Qihoo 360 actually built #
Zhou’s unveiling centered on a suite called “Yitian Tulong,” which contains two main components. Tulongfeng handles automated bug hunting, essentially an AI system that scans codebases for exploitable weaknesses. Yitianzhen covers the defensive side: incident response, threat detection, and remediation.
Qihoo 360 claims Tulongfeng has already flagged 3,432 software vulnerabilities. Of those, 105 have been confirmed by Chinese government sources.
Zhou himself was refreshingly candid about where Chinese models stand relative to their American counterparts. He estimated that Chinese systems lag US models by roughly 20-30% in raw capabilities. His proposed workaround is pragmatic rather than aspirational: instead of trying to build a single model that matches Mythos 5 head-to-head, deploy a multi-model “professional attack-and-defense team” strategy.
Zhou compared advanced cyber-AI models to “cyber nuclear weapons,” arguing that China cannot afford to let the US monopolize such technology.
Zhipu AI’s benchmark performance #
The more technically interesting announcement came from Zhipu AI, which presented results for its GLM-5.2 model. In targeted bug-finding tests, GLM-5.2 reportedly competed closely with Anthropic’s Claude Opus 4.8 when optimally configured.
GLM-5.2 still trails in broader functionality. Vulnerability detection is a narrow but strategically important slice of what frontier AI models can do. Being competitive in that specific domain doesn’t mean Zhipu AI has caught up across the board.
The export control backdrop #
Washington has spent the past several years tightening export controls on advanced AI chips and semiconductor equipment destined for China. Cybersecurity tools sit squarely in dual-use territory.
Anthropic has restricted access to Mythos 5’s vulnerability detection capabilities through a program called Project Glasswing, recognizing that an AI system good at finding bugs is also, by definition, an AI system good at finding exploits.
What this means for the cybersecurity landscape #
Zhou’s “cyber nuclear weapons” framing captures a real dynamic. Unlike conventional weapons, cyber capabilities are fundamentally software. They can be replicated, distributed, and improved at negligible marginal cost once the underlying model exists.
Investors watching this space should note the divergence in business models. US firms like Anthropic are building general-purpose frontier models with cybersecurity as one application. Chinese firms appear to be pursuing a more vertically integrated approach, building specialized tools for specific security tasks and combining them into coordinated systems. Zhou’s multi-model team strategy isn’t just a concession to capability gaps. It’s potentially a more deployable architecture for actual security operations, where reliability in narrow tasks matters more than impressive benchmark scores across dozens of categories.
The 20-30% capability gap that Zhou acknowledged is significant but not insurmountable, especially in a domain where creative engineering and domain expertise can compensate for raw model performance.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our