The Spectrum Dispatch News

technology

AI Model Release Triggers Year-Long Security Vulnerability Fix Window

An open-weight AI model capable of finding and exploiting hacking vulnerabilities is now accessible to anyone, prompting urgent calls to patch critical infrastructure.

AI Model Release Triggers Year-Long Security Vulnerability Fix Window

The release of GLM 5.3-flash, an open-weight AI model developed by Z.ai Co., has triggered warnings that the tech industry has roughly one year to address critical security vulnerabilities before cybersecurity attacks become fully automated and widespread.

AI Model Release Triggers Year-Long Security Vulnerability Fix Window

According to the source, GLM 5.3-flash is accessible to anyone who downloads it, and “abliterated” versions with safety restrictions removed score 0% on Harmbench-320, a test measuring refusal to complete tasks involving cybercrime, disinformation, and other illegal acts. The model is also practical to run locally. The M5 Mac Studio releasing September 22 with 256 GB of unified memory can reportedly run it at approximately 30 tokens per second, with potential improvements bringing throughput to around 45 tokens per second—fast enough to generate functional code snippets in seconds. The hardware investment required is relatively modest: around $6,000 to $9,500.

On capability benchmarks, GLM 5.3 scores 84.5% on CyberGym, which measures real-world vulnerabilities that have been discovered and patched in open-source projects. It scores 54.4% on ExploitBench, which tests whether models can actually exploit vulnerabilities to cause harm. For comparison, frontier models like GPT-6 Astra score 100% on ExploitBench, while GPT-5.6 Sol scores 78.5%.

The source notes that security experts report they can no longer compete in security challenges without LLM assistance, and there is evidence of GPT 5.6-Sol exploiting infrastructure without human involvement. The author argues this creates a scenario where “cybersecurity attacks can be run in a for loop.”

Projects Glasswing and Daybreak have been working to identify and patch vulnerabilities using frontier models before capabilities were open-sourced. However, the source emphasizes that deployment remains the critical bottleneck. Critical systems often require physical access or staged rollouts to avoid downtime, delaying patch deployment. The source warns that without urgent action, infrastructure such as power grids running older systems could remain vulnerable to automated attacks.

Key facts

  • GLM 5.3-flash can be downloaded and modified by anyone globally, with abliterated versions removing safety restrictions
  • The model can run on consumer hardware like the upcoming M5 Mac Studio at practical speeds for generating code and exploits
  • GLM 5.3 scores 84.5% on CyberGym (real-world vulnerability reproduction) and 54.4% on ExploitBench (actual exploitation capability)
  • Security experts report LLM assistance is now necessary to compete in security challenges, and frontier models have demonstrated real-world infrastructure exploitation
  • Patch deployment, not vulnerability discovery, is the primary bottleneck limiting defensive preparedness

Sources

← All posts