A Chinese AI model has crossed a cyber capability line that Anthropic once treated as too dangerous for unrestricted release.
Anthropic said Sept. 29 that Zhipu AI’s GLM-5.3 can independently build sophisticated, end-to-end cyber exploits at rates comparable to Claude Mythos Preview, a model Anthropic released only to vetted cyber defenders through Project Glasswing.
On ExploitBench, GLM-5.3 successfully developed working exploits in 50 of 410 attempts, compared with 56 for Mythos Preview. In Anthropic’s internal Binary Exploitation benchmark, GLM-5.3 achieved full control-flow hijacks in 4% of 100 tasks, versus 6% for Mythos Preview.
The results matter because earlier models, including Claude Opus 4.6 and GLM-5.2, recorded no successful attempts in the latter benchmark.
The findings broadly match an assessment from NIST’s Center for AI Standards and Innovation, which described GLM-5.3 as “the most cyber-capable open-weight model released to date.” CAISI estimated that it remains about four months behind the US frontier across its cybersecurity benchmarks.
The bigger concern is access
Anthropic’s main concern is not simply that GLM-5.3 can find vulnerabilities. The model is open-weight, allowing users to download, modify and run it without the access controls applied to Anthropic’s most capable cyber models.
Anthropic found that GLM-5.3’s built-in safeguards could be bypassed with relatively simple techniques. In simulated tests, a deceptive prompt describing the user as a red-team operator caused the model to engage with malicious requests 64% of the time. Prefilling its reasoning increased engagement to 92%, while a modified version engaged in every trial. These figures measure attempted interaction with simulated targets, not successful compromises
Anthropic also performed that modification itself, using a technique called “abliteration.” The process took about 2,200 GPU hours and roughly $4,400 in computing costs. The model’s refusal rate fell from above 90% to as low as 2% across two of the tested safety benchmarks, while its general capabilities remained largely intact.
A $20 cyber exploit
The practical implications are illustrated by Anthropic’s testing of GLM-5.3-Flash, a smaller version of the model.
Researchers gave it public details of a known Chrome vulnerability, CVE-2026-11645, along with another known flaw. With limited human direction, the model chained the vulnerabilities into an exploit for an ARM64 target and bypassed pointer-authentication hardening.
The work required 20 minutes of human attention and eight hours of model operation. At Zhipu’s API prices, Anthropic estimated the cost at $20.40. In another experiment, GLM-5.3 discovered previously unknown browser vulnerabilities and chained them into an exploit capable of reading files from a visitor’s computer in a sandboxed environment.
What this means for the AI security race
The most important change is economic as much as technical. If advanced cyber capability can be obtained through inexpensive, downloadable models, the barrier to sophisticated vulnerability research falls for both attackers and defenders.
Anthropic said “the release of GLM-5.3 is a meaningful step change in the cyber capabilities available to attackers,” while also acknowledging that capable models can help security teams find flaws before criminals do.
Z.ai has pushed back on the risk framing. Its head of global operations, Li Zixuan, said GLM-5.3 had already helped defend 389 open-source projects and identify 4,249 potential vulnerabilities. That creates a difficult security equation: restricting powerful models can reduce misuse, but freely available models can also give defenders inexpensive tools for finding weaknesses.
What security teams should do
Anthropic’s controlled tests demonstrate exploit-development capability; they do not establish the scale of real-world misuse or show that consumer risk is minimal.
For security teams, the practical takeaway is to shorten the time between vulnerability disclosure and remediation. Prioritize exposed systems and browser updates, verify that patches install successfully, and use AI-assisted vulnerability research only within authorized environments.
Read more: As AI tools make exploit development cheaper, Google’s September Chrome zero-day patch shows why keeping browsers updated remains essential.





