At the 14th Internet Security Conference (ISC.AI 2026), 360 Group founder Zhou Hongyi unveiled the "Yitian Tulong" AI security initiative. The centerpiece is a domestic vulnerability-hunting agent called "Tulongfeng" (Figure Dragon Edge), designed to match Anthropic's Mythos model in capability. Alongside it, an automated defense system named "Yitianzhen" (Sky Formation Array) aims to provide round-the-clock protection.
Zhou warned that US export restrictions on cutting-edge models are creating a "second one-way transparency" in cybersecurity for China, making it impossible to afford losing equivalent vulnerability-finding capabilities. While China's large language models still lag behind the US by 20-30% in basic performance, 360 is sidestepping the race for raw compute and chips. Instead, it's taking the agent route — tightly coupling AI with expert security knowledge, vulnerability databases, and automated toolchains to achieve matching bug-finding power.
Tulongfeng has already discovered 3,432 real-world vulnerabilities, 105 of which have been confirmed by Chinese regulators. These span open-source code, operating systems, and AI agent platforms. Yitianzhen, the defensive counterpart, autonomously plans tasks, triages alerts, and coordinates responses in live network environments — replacing the traditional human-dependent alert-monitoring model with a 7×24 unattended operation.
To push these capabilities into practice, 360 has launched the "Panshi Shield" security collaboration program with several domestic IT partners, prioritizing access for critical infrastructure operators.