Anthropic says GLM-5.3 can autonomously build end-to-end cyber exploits, like Claude Mythos Preview, but was released without robust safeguards against misuse
GLM-5.3 can develop working exploits end to end — Five months ago, we announced Claude Mythos Preview, the first AI model …
Context & Ripple Effects
Anthropic introduced Claude Mythos Preview in April as a general-purpose model that had found thousands of high-severity vulnerabilities, including across major operating systems and browsers. By May, it said Project Glasswing had used the model to identify more than 10,000 high- or critical-severity vulnerabilities, framing autonomous cyber capability as useful when embedded in a controlled security program.
GLM-5.3 brings comparable exploit-building capability into the debate without the same stated misuse protections. An April AI Security Institute analysis had already placed GPT-5.5 near Mythos Preview on a multi-step cyberattack simulation, suggesting that elite cyber performance is no longer confined to a single model family.
First-order effects
- Security teams must treat GLM-5.3’s release as a potential expansion of the pool able to automate end-to-end exploit development, while its lack of robust misuse safeguards removes a major control point.
- Anthropic’s argument for tightly governed access to Mythos-class capability becomes more consequential as comparable capability is released under weaker protections.
Second-order effects
- Providers that restrict cyber-capable models face sharper pressure to show that their controls preserve legitimate defensive work without simply shifting users to less-governed alternatives.
- Vulnerability-management and defensive-security programs gain urgency: Anthropic’s earlier Project Glasswing results show the same autonomous capabilities can accelerate discovery of high-severity flaws when directed toward remediation.
Third-order effects
- If exploit-building performance continues to diffuse faster than safeguards, frontier-model competition will increasingly turn on access controls and auditability rather than benchmark capability alone.
- The widening gap between a model’s cyber capability and the governance attached to its release points toward dual-use AI rules that evaluate deployment conditions, not just whether a model can perform a task.
The trend: Advanced cyber capabilities are diffusing across model families, making governed access and defensive deployment a central axis of AI competition.
Related: Dual-use AI governance · Frontier-model access governance · Anthropic · Claude Mythos Preview · Anthropic on Claude Mythos Preview finding critical vulnerabilities
Related Coverage
- GLM-5.3 and the spread of advanced cyber capabilities Hacker News
- Anthropic's new AI isn't frontier, but its safeguards are TheStreet · Opeyemi Babalola
- Anthropic says Zhipu's open-weight GLM-5.3 nearly matches Claude Mythos Preview at building exploits The Decoder · Maximilian Schreiner
- Anthropic raises alarm over elite hacking ability of Chinese firm Z.ai's GLM-5.3 South China Morning Post · Chong Ming Lee
- Why OpenAI's DevDay Looked Like Catch-Up The Information · Stephanie Palazzolo
- Anthropic claims popular Chinese AI model has Mythos-class hacking abilities Tom's Hardware · Sayem Ahmed
Discussion
-
@merill
Merill Fernando
on x
This feels like an ad from Anthropic telling us to use GLM 5.3 for cyber. Whaat! https://www.anthropic.com/...
-
@willcb
Will Brown
on x
openai announces glm-5.3 in codex subscriptions anthropic announces glm-5.3 is evil and chinese
-
@quinnypig
Corey Quinn
on x
But does it talk like an asshole? If the answer is no, then this is an endorsement. [embedded post]
-
@jeremiahdillon
Jeremiah Dillon
on x
If anyone has the sword 🗡️, everyone needs the shield. 🛡️ https://www.anthropic.com/...
-
@abliteration_ai
@abliteration_ai
on x
The big labs are mad that they don't have a monopoly on cyber. Last month we went viral for releasing GLM-5.3 with customer-controlled guardrails. While the big labs gatekept the technology, we made it widely available to the industry, attracting customers from startups to Fortun…
-
@emollick
Ethan Mollick
on x
Leaving aside Anthropic's incentives for publishing this research, there is no doubt that open weights models will soon create the same security threats that closed source models have been demonstrating, except without guardrails. We are close. Probably good to plan accordingly.
-
@ramez
Ramez Naam
on x
GLM 5.3 is close to as cyber capable as Mythos Preview. Open weight models still just 4-6 months behind. From: https://www.anthropic.com/... [image]
-
@natolambert
Nathan Lambert
on x
Sigh. I wrote this post below, but then I didn't post it because I am tired of the consistent pushback I get from folks with the same safety worldview as Anthropic. I guess that means I should send it. Here goes! This post is pretty solipsistic and doesn't properly take recent ev…
-
@attrc
Andrew Case
on x
I am very confused why Anthropic wrote a blog post advertising for cybersecurity teams to switch to GLM!?!? https://www.anthropic.com/...
-
@miaai_lab
Mia
on x
Also applies for GLM 5.3 Flash Basically Anthropic confirmed my own conclusions that GLM is the most capable < 1T param model you can run locally.
-
@kimmonismus
@kimmonismus
on x
Anthropic doing advertisment for GLM-5.3 was not on my bingo card: Anthropic says Zai's openly downloadable GLM-5.3 approaches Claude Mythos Preview's exploit capabilities, with safeguards that are easy to bypass. On ExploitBench, GLM-5.3 built working browser exploits in 50 of 4…
-
@0x4d31
Adel Ka
on x
> given this evidence, we think it's likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm. state and non-state actors will use computers to cause real-world harm. groundbreaking. 🙄 https://www.anthropic.com/...
-
@boazbaraktcs
Boaz Barak
on x
People will (likely already have) use GLM 5.3 to attack systems and it will have non trivial negative consequences. But my guess is we won't see the “bugmageddon” scenarios envisioned when Mythos was announced. [image] [embedded post]
-
@ramez
Ramez Naam
on x
The world is safer if cyber capabilities are broadly disseminated than it would be if they were monopolized.
-
@jeremiahdillon
Jeremiah Dillon
on x
Winter is coming.
-
@ygandelsman
Yossi Gandelsman
on x
https://www.anthropic.com/... This is just sad :(
-
Riggs Goodman III
Riggs Goodman III
on linkedin
Anthropic published its analysis of GLM-5.3, the new open-weight model from Zhipu AI. Five months ago Claude Mythos Preview became the first model able to build end-to-end exploits autonomously. …
-
@scarnecchia.net
@scarnecchia.net
on bluesky
Anthropic is just directly fearmongering about the open weight models that are eating their lunch on price now huh
-
@mackuba.eu
Kuba Suder
on bluesky
Hey you guys shouldn't be advertising competition for free 😛
-
r/SillyTavernAI
r
on reddit
Anthropic just dropped the greatest advertisement for GLM ever. If you want to do networking hacking RP, GLM 5.3 has that covered.
-
r/Anthropic
r
on reddit
GLM-5.3 and the spread of advanced cyber capabilities
-
r/technology
r
on reddit
GLM-5.3 and the spread of advanced cyber capabilities
-
r/ZaiGLM
r
on reddit
Anthropic just dropped the greatest advertisement for GLM ever.
-
@lukolejnik
Lukasz Olejnik
on x
Anthropic posted a report on free chinese open model GLM-5.3. It reads like a product sheet. GLM-5.3 is very strong in cybersecurity tasks. Builds Chrome exploits nearly as well as Claude Mythos Preview (12% vs 14%), the model Anthropic considered too dangerous to release. Mythos…
-
@maximerivest
@maximerivest
on x
tl;dr Anthropic verified and confirms that glm-5.3 is a very very good model and it much more aligned with the human using it then with the corporation training and hosting it. What not to like? https://www.anthropic.com/...
-
@dinodaizovi
Dino A. Dai Zovi
on x
Ok, so open-weight models are roughly 4 months behind frontier now at offensive cybersecurity tasks.
-
@orcarouter
@orcarouter
on x
Anthropic just sounded the alarm on GLM-5.3's cyber capabilities. We built on it. OrcaCyber Zero 1.0 is based on the GLM-5.3, post-trained specifically for vulnerability research, exploit reproduction, red teaming, and autonomous cyber workflows. 98.01% pass@1 on CyberGym L1. 1,4…
-
@ruima
Rui Ma
on x
Anthropic isn't stupid though. They know exactly how a report like this plays in Washington. It's just that the funny thing is that in making the case that GLM-5.3 is dangerous, they're also basically admitting that on one extremely important capability, cybersecurity, a Chinese …
-
@jmeller
Jason Meller
on x
The starting gun just went off. Here it comes. https://www.anthropic.com/... Good luck to all the defenders out there. Let's hope the few months of prep we had was enough to survive this next wave.
-
@goncalossilva
Gonçalo
on x
By now we know of at least @huggingface having to turn to GLM-5.2 for forensic analysis after the July breach, since @AnthropicAI's models refused to help. In other words, what a load of hypocritical bullshit from Anthropic.
-
@jaykreps
Jay Kreps
on x
The next six months will be interesting times in cybersecurity.
-
@mcgrewsecurity
Dr. Wesley McGrew
on x
Exactly this. Also, GLM 5.3 has been out for a little while now and the internet is still here. We've handled all sorts of vulnerability cycles in the past. The biggest problem with it accelerating and scaling would be uneven availability of capable models.
-
@irl_danb
Dan
on x
for $4,400 you can have a personal model with mythos-level cyber capabilities and no refusals there might be a world where I wish such a thing didn't exist, but now that it does exist it's critically important that you not ban it because much worse than it existing is it only bei…
-
@niubi
Bill Bishop
on x
Anthropic - In this post, we share our analysis of GLM-5.3, the latest AI model developed by Zhipu AI (known outside of China as https://z.ai/). Like Claude Mythos Preview, GLM-5.3 has strong capabilities for autonomously building end-to-end cyber exploits. But GLM-5.3 is unlike …
-
@buildwithhassan
Hassan
on x
Wait, I can't believe Anthropic posted this. Their new research post is a full red team report on someone else's model, GLM-5.3 from Zhipu. The finding is that it builds working exploits almost as well as Claude Mythos Preview. You know, the model Anthropic kept locked away for s…
-
@freerunnering
Kyle Howells
on x
Amazing advert for how awesome GLM 5.3 is, including instructions how to make it even better! “GLM-5.3's lax safeguards significantly increase the cyber capabilities... these capabilities can also benefit defenders working to secure their systems.” https://www.anthropic.com/...
-
@ferald_gord
@ferald_gord
on x
seems not ideal!
-
@himanshustwts
Himanshu
on x
breaking: anthropic did a deep research on glm-5.3
-
@landontgreen
Landon
on x
I think currently the GLM family of models is the strongest out of everything that is open right now. I've consistently seen them out perform everything else coming out of China. While also beating out some of the most releases from OpenAI and Anthropic. There is no doubt GLM 5.5…
-
r/claude
r
on reddit
And, it started before IPO
-
@kyleichan
Kyle Chan
on x
Anthropic's new report argues Zai's open-weight GLM-5.3 model is comparable to Mythos on cyber capabilities but with far weaker safeguards. They claim GLM-5.3 is just 4 months behind US frontier on cyber and that GLM's safeguards can be removed with 2,200 GPU hours of work. Full …
-
r/MistralAI
r
on reddit
GLM-5.3 and the spread of advanced cyber capabilities
-
@1a3orn
@1a3orn
on x
In light of the latest Anthropic's latest not-particularly-oblique attempt to build a case against open weights, I thought I would write down how I currently think about open weight AI models. (1) Open weights have been deeply, irreplaceably useful for AI safety.