Anthropic reported that Zhipu's open-weight model GLM-5.3 can build complete cyber exploits on its own, similar to Claude Mythos Preview. The company said the model's safeguards can be bypassed with simple methods, raising security concerns.
On the ExploitBench, GLM-5.3 built a working exploit in 50 of 410 attempts, while Mythos Preview managed 56. Anthropic also ran an internal binary exploitation benchmark, where GLM-5.3 took full control of the target program in 4 percent of tasks, compared to 6 percent for Mythos Preview.
GLM-5.3, unlike other models with comparable skills, shipped without effective safeguards. Anthropic deliberately held Mythos Preview back, giving access only to select defenders through Project Glasswing so they could get a head start. The company says those defenders have since found more than 10,000 vulnerabilities in critical software.
"Within a single day and with little human attention, the model found several previously unknown vulnerabilities in the JavaScript engine of a widely used browser," said Maximilian Schreiner, a researcher at Anthropic. "It then chained them into a web page that can read any file on a visitor's computer, and in the test it pulled a private SSH key."
The announcement follows Anthropic's release of its own analysis on GLM-5.3's capabilities, which it claims are close to those of its own models. Anthropic's warning also serves its business, as the company wants to bring Claude's cyber capabilities to more defenders.
Anthropic did not say whether the model's open-weight nature makes it more vulnerable to misuse, and the company raised concerns about the risks of such models being used by state and non-state actors. The company points to its own reports and those from other US labs documenting attackers who already use AI.
Source: thedecoder