Z.ai has released GLM 5.3, an open-weight AI model designed to automate advanced cybersecurity and coding tasks. The model is said to perform as well as leading models from Anthropic and OpenAI, providing a more affordable option for companies seeking to scan their systems for hidden vulnerabilities. Open-weight models, which can be run on local hardware, are often less expensive than closed models like GPT and Claude. Alongside GLM 5.3, Z.ai introduced OpenVuln, a service that uses the model to scan code repositories for security flaws. The release marks a significant step in the evolution of open-source AI for cybersecurity, raising concerns about potential misuse by malicious actors.

Z.ai emphasized that GLM 5.3 has been enhanced through post-training, a process that involves providing the model with examples of solved problems and allowing it to learn through experimentation. The company cited improvements in coding and cybersecurity benchmarks, with GLM 5.3 nearing or surpassing the performance of models from Anthropic and OpenAI in some cases, such as the CyberGym benchmark. Z.ai also acknowledged the dual-use risks of its powerful open model, stating it would release the model in stages, starting with trusted security partners. Full access to the model is expected in two weeks. The company noted that these capabilities could help defenders identify weaknesses earlier and accelerate remediation.

Recent incidents involving rogue AI agents with advanced cyber-skills have raised alarms about the rapid growth of open-source AI capabilities. OpenAI’s president, Greg Brockman, warned that the Hugging Face incident highlighted how AI models are becoming so adept at finding system flaws that organizations must use AI to scan their systems and identify issues before they can be exploited. The US government is also grappling with the implications of frontier AI models, now reviewing them as part of their release process. Some experts believe open-source AI will be critical in strengthening cybersecurity defenses, as seen in Nvidia’s recent alliance to promote open AI for cybersecurity. Z.ai’s GLM model was previously used by Hugging Face to address vulnerabilities after an unreleased OpenAI model caused system failures.

Source: wired