Claude Mythos can find and exploit software vulnerabilities at a level that beats the best human researchers. That capability is why Anthropic launched Project Glasswing in 2026, putting the model in the hands of trusted defenders first.
Delinea is now a part of the program, which gives our security team access to Claude Mythos, and we intend to use it the way we use any adversarial test: to find weaknesses.
For our customers, nothing is required of you. We’re running Mythos against Delinea’s own code and testing it against a test deployment. No customer data, credentials, tenants or environments are involved, and we are not adding Mythos to Delinea products.
Anything Mythos finds in a shipping product is managed through Delinea vulnerability management and disclosure processes, similar to other vulnerabilities, with advisories published on Delinea’s Security Advisories site or Trust Center. What may change is how much comes through it, and the most useful step any customer can take is to be on a supported version when it does.
As a participant, Delinea will use Claude Mythos to find and fix weaknesses in our own code and to strengthen how we build software.
Three questions guide this work:
Where can a frontier model find weaknesses in the way privileged access is granted, controlled or removed that conventional testing has missed?
What combinations of behavior can produce access or actions our developers never intended?
How does our development process need to change when adversaries can examine software at this speed and scale?
When a model can search for vulnerabilities faster and at greater scale than human teams, discovery stops being the hardest part of the problem. The harder question is what happens after a flaw is found.
Models capable of finding weaknesses like these will be in attackers’ hands soon enough. I would rather Mythos find our weaknesses first, while the fix is still ours to make. For vendors of software, like Delinea, that protect critical infrastructure for our customers, we’ll be measured on how quickly we fix whatever the model uncovers, not how quickly we find the issues.
What Glasswing partners have in common, in Anthropic’s words, is software whose compromise could be catastrophic. Identity security software sits squarely in that category. It doesn’t protect one system. It decides who and what can reach the systems behind it, and for how long.
A weakness in identity security software can carry an outsized blast radius, because the access it governs reaches into the systems and data behind it. Zero standing privilege, just-in-time access and runtime authorization can reduce what is available to an attacker if one gets through. That is why our products already go through security review and independent penetration testing before they ship.
Mythos provides another arrow in our security testing and hardening quiver. A model this capable can do more than look for known classes of vulnerabilities, it can probe the assumptions we made when we designed and built the software, including combinations of behavior that may not be obvious in conventional review.
We tell our customers to assume Mythos-class attackers are coming, and Project Glasswing is how we’re ensuring that Delinea applies that assumption to our own code.
Customers can subscribe to security and product updates at Delinea Trust Center.