Skip to main content
Tech Insights

Hunting Our Own Vulnerabilities First: Tanium’s Frontier AI Security Commitment

Tanium’s customers span critical infrastructure sectors, including some of the largest banks, hospital systems, and government agencies in the world. They trust our agent on their most sensitive endpoints, which means that the software we ship must meet the high standards they set for themselves. That’s why we hunt our own vulnerabilities before anyone else can.

We’ve recently announced that Tanium is participating in Anthropic's Project Glasswing, testing Claude Mythos 5 for defensive security work, and we've initiated similar efforts with other partners in private preview. Across our development lifecycle, we've been experimenting with frontier AI models for vulnerability discovery – and we want to share what we’re learning, along with a practical consequence our customers should plan for.

Raising the ceiling on traditional application security practices

For years, Tanium has continuously evaluated our product according to industry best practices. Tanium regularly performs application penetration testing, by its internal security team of product experts, as well as reputable third-party consultancies. Tanium’s R&D Security Team has integrated fuzzing, SAST, and DAST toolchains into our development lifecycle. While our security program is mature, we are also adopting AI technologies that measurably improve the security of our software.

SAST tools can find specific classes of vulnerabilities that can be expressed as a pattern, such as a tainted value reaching a sink or a known-bad API call. DAST tools can find textbook web application vulnerabilities such as SQL injection or common misconfigurations. However, these tools perform poorly at finding vulnerabilities that require a deeper understanding of the expected behavior and also struggle with accounting for interaction between several components. The signal-to-noise ratio for these tools is very low, and improving the rate of true-positives requires extensive tuning and ongoing maintenance.

Until now, complex bugs were usually discovered by engineers who understand the architecture, threat model, and codebase for our software deeply. However, scaling security capabilities purely by adding headcount is neither a sustainable nor realistic solution.

In the past year, frontier AI models have advanced significantly in their cybersecurity capabilities. They can now parse through complex codebases and reason about the intended functionality while performing vulnerability discovery. While they still make mistakes and require supervision, our experiments have uncovered numerous security vulnerabilities that our security engineers have confirmed as impacting. In our internal testing, the signal-to-noise ratio was meaningfully better than what we see from traditional security tooling. With these improved capabilities, scaling vulnerability identification and remediation with frontier AI has become an urgent priority for our team.

Different tools find different bugs in the same code

Our security engineers built a custom evaluation harness around a general-purpose frontier model. This harness encodes Tanium's threat model, the trust boundaries that exist in our architecture, the behaviors that are intended by design, and a corpus of vulnerability data drawn from years of our own research and disclosure history. This harness uncovered the types of vulnerabilities that require deep system knowledge and context – the kind traditional tooling would have failed to identify.

Separately, we ran various models and agentic scanning systems against the same codebase. These capable harnesses were given no Tanium-specific context, and they each found valid bugs distinct from those found by other harnesses.

Across the findings reported by these tools, the overlap is considerably smaller than we expected. We're not yet ready to say definitively whether that's a property of the models, the harness, our codebase, or how early we are, but the short-term practical implication is already clear enough to act on: agentic security workflows should not rely on a single model or vendor and should incorporate institutional context to improve performance.

We continue to invest in building and tuning the context we feed these tools, pushing what's possible here rather than settling on the first approach that works.

Tanium is increasing its security patch volume and velocity

Our commitment to providing maintenance releases to our on-premises customers on at least a monthly cadence remains unchanged. What will change is the frequency of out-of-band releases and the volume of vulnerabilities disclosed for each release. We hold ourselves to aggressive SLAs for remediating vulnerabilities we assess as exploitable, measured in days for the most critical issues, and we intend to keep meeting them, even as our discovery capability improves.

This means you should anticipate an increase in security advisories, CVE records, and security patches from us over the coming months as we continue to apply and evolve these techniques across our stack. We want to set that expectation clearly, because a rising CVE count is easy to misread. It is not a signal that our software is getting worse. Rather, we are getting better at uncovering latent security issues that are hard to find.

This is a pattern that our peers in the software industry have observed: Mozilla patched 271 vulnerabilities as a result of their first evaluation of Mythos and Microsoft patched more than 900 security vulnerabilities on September 9th’s Patch Tuesday.

In addition to proactively hunting our codebase for vulnerabilities and patching them promptly, we transparently inform our customers about known security issues. We'll continue to meet our obligations as a CVE Numbering Authority and responsibly disclose these vulnerabilities (see https://security.tanium.com for published advisories), as this information enables customers to evaluate exposure and plan remediation accordingly. We recognize that patching can present operational challenges for our customers, and we don't take that lightly. But the reality is that the pace of vulnerability discovery and exploit development is accelerating for defenders and attackers alike, and patch cycles in the industry will need to get faster as well to keep our systems secure.

Tanium is committed to supporting our customers in streamlining patching for their Tanium deployments. All customers have access to Tanium’s Endpoint Configuration, which is designed to enable safe, seamless, and frequent upgrades to the Tanium Client and endpoint tooling. On-premises customers must also upgrade their Tanium backend to benefit from all these security patches. Our semiannual maintenance releases include limited code changes, targeting critical and security bugs, to provide the predictability and stability our customers need to implement rapid upgrade cycles.

What’s next?

Tanium’s R&D Security Team will continue to develop and apply frontier AI cyber capabilities to our software products and our security operations. As we learn more about harness design, triage workflow, and what the multi-model coverage gap looks like, we intend to share our research publicly and continue to do the right thing for the security of Tanium’s customers. Our customers rely on Tanium for their IT and security operations so they can focus on their critical business challenges — and hunting our own vulnerabilities first, before anyone else can, is how we keep earning that trust.

Tanium's statements and content regarding its plans, directions, and intent are confidential and subject to change without notice at Tanium's sole discretion. Information regarding potential future products or functionality is intended to outline Tanium's general product direction and it should not be relied on in making a purchasing decision, nor is it incorporated into any contract. It is not a commitment, promise, or legal obligation. The development, release, and timing of any future products or functionality remain at Tanium's sole discretion