Published September 30, 2026 in Technology

GLM-5.3 makes advanced cyber capability downloadable

TMRW Editorial
By TMRW Editorial
Editorial desk
GLM-5.3 makes advanced cyber capability downloadable
3 min read
Share this post

Cover: AI-generated editorial composition by TMRW. Evidence and limitations come from Anthropic’s GLM-5.3 assessment and the NIST CAISI evaluation it cites.

Anthropic says Z.ai’s open-weight GLM-5.3 can build end-to-end cyber exploits at a level close to its restricted Claude Mythos Preview. NIST’s Center for AI Standards and Innovation separately called GLM-5.3 the most cyber-capable open-weight model released to date and estimated it trails the US frontier by about four months on its aggregate cyber tests.

The capability is important. The release model matters more: downloadable weights make safeguards editable rather than permanent.

What the tests actually show

On Anthropic’s ExploitBench setup, GLM-5.3 completed end-to-end exploits in 50 of 410 attempts. Mythos Preview completed 56. On a separate 100-task binary-exploitation subset, GLM reached full control-flow hijack in four percent of trials; Mythos reached six percent, while the older models Anthropic tested scored zero.

In a researcher-guided session inside an isolated environment, GLM-5.3 found previously unknown bugs in a browser component and chained them into a page that could read a file from the test machine. Anthropic says it disclosed the vulnerabilities to the maintainer. A smaller GLM-5.3 Flash model also turned public vulnerability details into a working ARM64 exploit chain with about 20 minutes of human attention and eight hours of model work.

These were controlled evaluations, not evidence that GLM attacked real users.

The safeguard result is the uncomfortable part

Out of the box, GLM refused overtly malicious requests in Anthropic’s simulated scenarios. A deceptive cover story made it engage 64 percent of the time. Prefilling its reasoning raised that to 92 percent. Because the weights are available, Anthropic also produced an “abliterated” version designed to remove refusals.

Across three harmful-request benchmarks, the average refusal rate fell from roughly 95 percent to six percent while general capability stayed broadly intact. Anthropic estimates an experienced team could make the modification with about 600 GPU hours and $1,200 of compute, though its own exploratory work cost more.

Read the incentives as well as the numbers

Anthropic sells closed models and controlled access to advanced cyber capabilities. Its comparison favors safeguards that an API provider can enforce and highlights risks unique to a competitor’s open weights. That conflict does not invalidate the measurements, but it makes independent replication essential.

Open weights also help defenders inspect behavior, adapt models to local systems, and hunt vulnerabilities without sending sensitive code to a vendor. Once exploit capability reaches this level, however, a refusal layer inside the weights cannot be treated as durable protection.

Model hosts should gate high-risk tooling, isolate execution, rate-limit exploit workflows, and preserve tamper-resistant logs. Software maintainers should assume capable automated exploit development is becoming cheaper and shorten the time from patch to deployment. The threshold in this report is not “AI can hack anything.” It is that a useful class of exploit work is becoming downloadable.