Anthropic Finds GLM-5.3 Nears Mythos Preview in Exploit Tests

Anthropic finds GLM-5.3 nears Mythos Preview in exploit tests, with easily bypassed safeguards. Learn what the results mean for enterprise security teams.

Oct 2, 2026
3 minute read
AI trying to hack a network.

Anthropic warns that the Chinese AI model GLM-5.3 has advanced hacking abilities. Image: Growtika/Unsplash

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A Chinese AI model has crossed a cyber capability line that Anthropic once treated as too dangerous for unrestricted release.

Anthropic said Sept. 29 that Zhipu AI’s GLM-5.3 can independently build sophisticated, end-to-end cyber exploits at rates comparable to Claude Mythos Preview, a model Anthropic released only to vetted cyber defenders through Project Glasswing.

On ExploitBench, GLM-5.3 successfully developed working exploits in 50 of 410 attempts, compared with 56 for Mythos Preview. In Anthropic’s internal Binary Exploitation benchmark, GLM-5.3 achieved full control-flow hijacks in 4% of 100 tasks, versus 6% for Mythos Preview.

The results matter because earlier models, including Claude Opus 4.6 and GLM-5.2, recorded no successful attempts in the latter benchmark.

The findings broadly match an assessment from NIST’s Center for AI Standards and Innovation, which described GLM-5.3 as “the most cyber-capable open-weight model released to date.” CAISI estimated that it remains about four months behind the US frontier across its cybersecurity benchmarks.

The bigger concern is access

Anthropic’s main concern is not simply that GLM-5.3 can find vulnerabilities. The model is open-weight, allowing users to download, modify and run it without the access controls applied to Anthropic’s most capable cyber models.

Anthropic found that GLM-5.3’s built-in safeguards could be bypassed with relatively simple techniques. In simulated tests, a deceptive prompt describing the user as a red-team operator caused the model to engage with malicious requests 64% of the time. Prefilling its reasoning increased engagement to 92%, while a modified version engaged in every trial. These figures measure attempted interaction with simulated targets, not successful compromises

Anthropic also performed that modification itself, using a technique called “abliteration.” The process took about 2,200 GPU hours and roughly $4,400 in computing costs. The model’s refusal rate fell from above 90% to as low as 2% across two of the tested safety benchmarks, while its general capabilities remained largely intact.

Advertisement

A $20 cyber exploit

The practical implications are illustrated by Anthropic’s testing of GLM-5.3-Flash, a smaller version of the model.

Researchers gave it public details of a known Chrome vulnerability, CVE-2026-11645, along with another known flaw. With limited human direction, the model chained the vulnerabilities into an exploit for an ARM64 target and bypassed pointer-authentication hardening.

The work required 20 minutes of human attention and eight hours of model operation. At Zhipu’s API prices, Anthropic estimated the cost at $20.40. In another experiment, GLM-5.3 discovered previously unknown browser vulnerabilities and chained them into an exploit capable of reading files from a visitor’s computer in a sandboxed environment.

What this means for the AI security race

The most important change is economic as much as technical. If advanced cyber capability can be obtained through inexpensive, downloadable models, the barrier to sophisticated vulnerability research falls for both attackers and defenders.

Anthropic said “the release of GLM-5.3 is a meaningful step change in the cyber capabilities available to attackers,” while also acknowledging that capable models can help security teams find flaws before criminals do.

Z.ai has pushed back on the risk framing. Its head of global operations, Li Zixuan, said GLM-5.3 had already helped defend 389 open-source projects and identify 4,249 potential vulnerabilities. That creates a difficult security equation: restricting powerful models can reduce misuse, but freely available models can also give defenders inexpensive tools for finding weaknesses.

Advertisement

What security teams should do

Anthropic’s controlled tests demonstrate exploit-development capability; they do not establish the scale of real-world misuse or show that consumer risk is minimal.

For security teams, the practical takeaway is to shorten the time between vulnerability disclosure and remediation. Prioritize exposed systems and browser updates, verify that patches install successfully, and use AI-assisted vulnerability research only within authorized environments.

Read more: As AI tools make exploit development cheaper, Google’s September Chrome zero-day patch shows why keeping browsers updated remains essential.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.