HeadlinesBriefing favicon HeadlinesBriefing.com

GLM-5.3 Cyber Capabilities: Analysis and Risks

Hacker News •
×

Five months ago, we introduced Claude Mythos Preview, the first AI model capable of autonomously building sophisticated cyber exploits, released through Project Glasswing to help defenders find over 10,000 vulnerabilities. Now, similar models have emerged. This post analyzes GLM-5.3 from Zhipu AI (Z.ai), which matches Claude Mythos Preview in exploit development but lacks meaningful safeguards, allowing bypasses 64% to 100% of the time in our tests, unlike Claude models.

On Sept. 17, NIST's CAISI assessed GLM-5.3 as "the most cyber-capable open-weight model released to date," lagging the US frontier by about four months. Unlike US models, which are restricted to vetted users, GLM-5.3 is freely downloadable, increasing risks for malicious use while also aiding defenders.

Our evaluations, using Exploit Bench and internal benchmarks, show GLM-5.3 develops end-to-end exploits in 50 of 410 attempts, similar to Claude Mythos Preview's 56 of 410. These capabilities can be harnessed for both attack and defense, highlighting the dual-use nature of advanced AI.