Tanium has joined Anthropic’s Project Glasswing, applying Claude Mythos 5 to its own production codebase to find and fix vulnerabilities before attackers can exploit them. The Autonomous IT company announced its participation on 16 September, aiming its use of the frontier model at the software that IT and security teams across thousands of enterprises rely on to manage their endpoint estates.
“Every line of code Tanium ships is code that IT and security operators are trusting to protect their most critical systems,” said Christian Hunt, chief engineering officer at Tanium. “Project Glasswing gives us access to a frontier AI capability that lets us find and fix vulnerabilities before they can be exploited and create harm for the organizations that depend on us.”
Applying frontier AI to enterprise security
Tanium says it has been tracking frontier AI’s growing ability to surface vulnerability categories that conventional scanning tools miss, some of which have sat latent in codebases for years. Its Project Glasswing participation extends work already underway using general-purpose AI models on its own code, now with access to Claude Mythos specifically for vulnerability research.
Tanium serves large financial institutions, healthcare systems and government agencies, meaning the security of its own software has a direct bearing on the security posture of those customers. The company says it will publish what it learns from the engagement, covering workflows, triage practices and how frontier AI is changing effective code security, and will continue meeting its obligations as a CVE Numbering Authority by publishing CVE records and advisories for vulnerabilities found in its products.
Why it matters for Asian enterprises
The announcement comes as Anthropic’s own call for frontier AI labs to moderate the pace of capability development has drawn public support elsewhere in the industry. Tanium’s move underlines a separate point: even if development at the major labs slows, the risk from attackers already using AI to find and exploit software flaws does not. For enterprises in the region managing large endpoint estates, transparency from vendors on how they are hardening their own code against AI-assisted attacks is becoming a more direct factor in vendor risk assessments.

