Chinese cybersecurity company 360 unveils new AI tools: Tulongfeng, which it claims is “China's version of Mythos”, and Yitianzhen, to automate cyber defense
Context & Ripple Effects
360 had already reported using an AI-powered agent to uncover previously unknown vulnerabilities, making Tulongfeng and Yitianzhen a productization step rather than an isolated AI announcement.
Follow-up coverage places Tulongfeng alongside Sakana AI’s Fugu as regional efforts claiming to match restricted frontier cyber models amid US export constraints. That makes the launch relevant to the availability of locally developed cyber-AI tooling.
First-order effects
- 360 expands its cyber-defense offering with tools positioned for automated defensive work, potentially giving its existing security customers AI-assisted vulnerability discovery and response options.
- The company is publicly benchmarking Tulongfeng against a named foreign model, raising the competitive stakes for its technical credibility in China’s cybersecurity market.
Second-order effects
- Domestic security vendors and enterprise buyers will face greater pressure to demonstrate whether their AI systems can find, triage, and remediate vulnerabilities reliably rather than merely generate alerts.
- Export restrictions on leading foreign models can increase the strategic value of locally developed cyber models, while making independent evaluation of capability claims more important for customers.
Third-order effects
- If these tools prove operationally useful, cyber defense could shift from analyst-led workflows toward AI agents that continuously identify and prioritize weaknesses, changing how security teams allocate skilled staff.
- The emergence of regionally developed alternatives to restricted frontier models points to a more fragmented cybersecurity-AI stack, with capability, access, and trust increasingly shaped by national technology boundaries.
The trend: This is one data point in the move from general-purpose AI toward specialized, locally available agents for high-stakes cybersecurity operations.