Strategic Report  ·  2026-10-04

GLM-5.3 and the spread of advanced cyber capabilities

Strategic ReportHigh impactGlobal
Anthropic's Frontier Red Team published an evaluation of GLM-5.3, Zhipu AI's (Z.ai) open-weight frontier model, finding that attackers can bypass its safeguards between 64% and 100% of the time with simple techniques in simulated tests. GLM-5.3 develops end-to-end exploits at a rate comparable to Claude Mythos Preview (50 of 410 attempts on ExploitBench vs. 56), matching the first model able to autonomously build end-to-end exploits — but, unlike Anthropic's safeguarded releases, it is freely downloadable. In human-expert sessions the model identified previously unknown vulnerabilities and chained them into working exploits that can read arbitrary files from a victim's computer, and it delivered full control-flow hijacks in 4% of Binary Exploitation trials where earlier open models completed none. Citing NIST CAISI, the report notes GLM-5.3 is 'the most cyber-capable open-weight model released to date' and assesses that its lax safeguards 'significantly increase the cyber capabilities available to malicious actors.'
For CISOs and security leaders this is a concrete, quantified statement that exploit-engineering-grade capability is now circulating in an open-weight model anyone can download — a material shift in the external threat baseline that should inform defensive investment and critical-software exposure reviews.
Review whether personnel, supply chain, or internet-facing assets could be exposed to GLM-5.3-enabled exploit chains and accelerate mitigation of unpatched browser, driver, and network-device vulnerabilities.
Anthropic Frontier Red Team — GLM-5.3 and the spread of advanced cyber capabilities
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →