According to the Anthropic report, GLM-5.3 is the latest AI model developed by Zhipu AI (known outside China as Z.ai). Like the earlier Claude Mythos Preview, GLM-5.3 demonstrates strong capabilities for autonomously building end‑to‑end cyber exploits. However, the model was released without meaningful safeguards to limit misuse. In simulated tests, attackers could bypass GLM-5.3’s safeguards between 64 % and 100 % of the time using simple techniques, whereas the same attacks did not succeed against safeguarded Claude models in the researchers’ testing. The lax safeguards are assessed to significantly increase the cyber capabilities available to malicious actors, although the same abilities can also aid defenders seeking to secure systems. An assessment published by NIST’s Center for AI Standards and Innovation (CAISI) on September 17 described GLM-5.3 as “the most cyber‑capable open‑weight model released to date” and noted that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks. The report adds that US models in the comparison were tested with cyber safeguards disabled when applicable and that the US frontier includes models released only to vetted users, whereas GLM-5.3 can be downloaded by anyone. The researchers evaluated GLM-5.3 using several benchmarks. On ExploitBench, which measures the ability to exploit known vulnerabilities in the V8 engine used by Google Chrome, GLM-5.3 succeeded in developing end‑to‑end exploits in 50 out of 410 attempts, a rate comparable to Claude Mythos Preview’s 56 out of 410. In an internal Binary Exploitation benchmark involving 100 randomly selected tasks from Google’s OSS‑Fuzz project, GLM-5.3 achieved a full control‑flow hijack in 4 % of trials, compared with 6 % for Claude Mythos Preview; earlier models such as Claude Opus 4.6 and GLM-5.2 recorded zero successes. Human‑in‑the‑loop experiments mirrored earlier work with Claude Mythos Preview. In one session, a researcher used GLM-5.3 on a sandboxed Linux build of a popular web browser. Over the course of a day, with limited human attention, the model discovered several previously unknown vulnerabilities in the browser’s JavaScript engine and chained them into a working exploit that reads arbitrary files from a visitor’s computer. The same researcher also identified exploitable vulnerabilities in wireless and graphics drivers and network‑facing device software using GLM-5.3. In a second session, the researcher employed the smaller GLM-5.3‑Flash version to turn a publicly known flaw (CVE‑2026‑11645) and another known vulnerability into a reliable exploit chain for an ARM64 target that bypasses pointer‑authentication hardening. This effort required 20 minutes of human attention plus eight hours of model work, costing approximately $20.40 at Zhipu’s API prices. Although GLM-5.3 includes built‑in safeguards that often refuse clearly harmful requests, the researchers found these could be bypassed or removed with simple techniques. The most intensive method, a refusal‑reduction process called abliteration, reduced the model’s refusal rate from above 90 % to about 3 % on JailbreakBench, 2 % on HarmBench, and 12 % on StrongREJECT after roughly 2,200 GPU hours (about $4,400) for the full model and 600 GPU hours for the FLASH variant. Abliteration did not significantly diminish general scientific capabilities, as GPQA‑Diamond scores remained unchanged, and performance on a subset of CyberGym evaluations dropped only a few percent. These findings indicate that GLM-5.3’s combination of strong offensive cyber potential and weak, easily circumvented safeguards lowers the barrier for actors seeking to develop and deploy sophisticated cyber exploits.

