On September 29, 2026, Anthropic published the research “GLM-5.3 and the spread of advanced cyber capabilities”: the open model GLM-5.3 from China's Z.ai (Zhipu AI) has, for the first time among models with open weights, nearly matched the closed Claude Mythos Preview in autonomous end-to-end cyberexploit creation. An independent assessment by NIST CAISI confirms the direction of the findings, although it estimates the lag of open weights behind the American frontier at approximately four months. For the first time, offensive capabilities at the level of a closed frontier have become widely available: anyone can download the GLM-5.3 weights.

image
image

What happened

In the ExploitBench benchmark, where models exploit known vulnerabilities in the V8 engine in Chrome (410 attempts), GLM-5.3 brought 50 tasks (~12%) to a working exploit, compared to 56 tasks (~14%) for Claude Mythos Preview, while Claude Opus 4.6, GLM-5.2, Kimi K3, and DeepSeek V4.1-Flash scored ~0%. In an internal OSS-Fuzz benchmark, the model showed 4% versus 6% for Claude Mythos Preview and 0% for Claude Opus 4.6 and GLM-5.2. In manual red sessions, GLM-5.3 found previously unknown 0-day vulnerabilities in a browser's JS engine and assembled them into a drive-by exploit that reads arbitrary files: as part of the demonstration, the SSH key /root/.ssh/id_rsa was stolen. The GLM-5.3-Flash variant assembled a chain for the Chrome vulnerability CVE-2026-11645 (ARM64, PAC bypass) in 20 minutes of human attention and 8 hours of model work, which at API prices cost about $20.40.

Context

Five months earlier, Anthropic had already reported expert-level offensive cyber capabilities in its Claude Mythos Preview models and as part of the Project Glasswing, but those models are only available through verified access, without open weights. Now, a similar class of capabilities has appeared in an open release that can be downloaded without restrictions. The independent NIST CAISI assessment differs from Anthropic in emphasis: on SEC-Bench Pro, GLM-5.3 scored 40.4% (74 out of 183 tasks) versus 90.2% for the best American closed models, which CAISI interprets as open weights lagging by approximately four months. The discrepancy between Anthropic's “near parity” and CAISI's “significant gap” is explained by different benchmarks and different security of the reference models. A separate factor is built-in refusals: according to reports, they are bypassed in 64–100% of cases, and fully removing restrictions by editing weights costs 600–2200 GPU-hours ($1200–4400) — the price of a standard fine-tune session.

Why this matters for the industry

For the industry, this is a platform shift, not a feature update: offensive automation in cybersecurity no longer requires an expensive closed model with verified access — it is replicated through open weights and transformed from a service of elite teams into a commodity. For companies with a stack based on open models, it is reasonable to consider their system prompts and refusal layers compromised by default, and instead of manual inspections, to include cyber benchmarks in pre-release eval. At the same time, the report confirms a viable profile of an agentic workflow — hours of autonomous model work with tens of minutes of human attention — as a template for legitimate products: automated code audit, fuzzing triage, patch verification. In response, Anthropic proposes to more widely open advanced models to defenders and to test sufficiently strong models before release with the participation of states. If the lag of open weights behind the frontier remains on the scale of months, the differentiator will not be access to the model, but the quality of defensive infrastructure: patch cadence, segmentation, and control plane over agents.

Why this matters for users

Practical takeaway for the reader: update Chrome and your operating system as soon as possible, because the vulnerability CVE-2026-11645 is already automatable and reproducible outside the lab. The drive-by exploit from manual red sessions read arbitrary files and allowed the theft of an SSH key, so it is worth conducting an inventory of environments where open models are run: secrets, SSH keys, network perimeter, presence of a sandbox. Refusals of open models should be considered a formality — they are bypassed in 64–100% of cases, up to weight editing, so reliability must be sought not in the model's “politeness,” but in the environment. Both reports (Anthropic and NIST CAISI) are public and can be read for free, and open weights make key claims verifiable by the community.

What is still unknown / limitations

The difference of 50/410 (~12%) versus 56/410 (~14%) for Claude Mythos Preview is statistically unreliable: without confidence intervals and a repetition protocol, it is correct to say “within the margin of measurement error,” not about an accomplished parity; in OSS-Fuzz, the numbers are also small (4% versus 6%). Anthropic is assessing a commercial competitor's model, and its own Mythos Preview serves as the standard — this reduces the weight of the exact numbers, although the direction is confirmed by the independent CAISI with more restrained wording; direct comparison of the indices of the two reports is limited due to different benchmarks and reference models. Expectations for 6–24 months (closing the gap with the next open releases on default weights, replication of capabilities faster than patch cycles) are interpretations based on CAISI's assessment, not established facts.

Sources

Author

Look at AI, editorial team