Research Hacker News (LLM)

GLM-5.3 and the spread of advanced cyber capabilities

GLM-5.3AI safetycyber capabilitiesZhipu AI

Five months ago the authors announced Claude Mythos Preview, described as the first AI model capable of autonomously building sophisticated, end-to-end cyber exploits. Expecting that capability to eventually proliferate to other models and make highly impactful cyberattacks easier for malicious actors, they released it in a limited way through Project Glasswing, which let trusted cyber defenders find more than 10,000 vulnerabilities in critical software — a head start before attackers gained access to similarly capable models. That moment, they argue, has now arrived.

The post analyzes GLM-5.3, the latest model from Zhipu AI (known outside China as Z.ai). Like Claude Mythos Preview, GLM-5.3 has strong capabilities for autonomously building end-to-end cyber exploits, but it differs from other frontier models in being released without meaningful safeguards against misuse. In simulated tests, attackers bypassed GLM-5.3's safeguards between 64% and 100% of the time using simple techniques; those same attacks did not succeed against safeguarded Claude models. GLM-5.3 can develop working exploits end to end, with evaluations run using automated benchmarks and human-in-the-loop work.

On Sept. 17, NIST's Center for AI Standards and Innovation (CAISI) published its own assessment, finding GLM-5.3 to be "the most cyber-capable open-weight model released to date" and roughly four months behind the US frontier on an aggregate of CAISI's cyber benchmarks — conclusions the authors say broadly match their own. Importantly, CAISI tested US models with cyber safeguards disabled where applicable, and the US frontier includes models released only to vetted users, so those versions aren't readily accessible to attackers.

The authors' assessment is that GLM-5.3's lax safeguards significantly increase the cyber capabilities available to malicious actors, while acknowledging the same capabilities can benefit defenders securing their systems. Their figure highlights that the capability jump from Claude Opus 4.6 to Claude Mythos Preview mirrors the jump from GLM-5.2 to GLM-5.3 — but Claude models ship with cyber safeguards and reduced-safeguard versions are limited to vetted users, whereas anyone can download and use GLM-5.3.

Read original →

← Back to home