
Tech • AI • Robotics • Game
A new assessment of GLM 5.3, an open-weights Chinese AI model, suggests advanced cyberattack capabilities are becoming cheap and widely accessible, forcing defenders to focus on speed, visibility and automated response rather than scarcity.
GLM 5.3, developed by Zhipu AI, was measured on a benchmark for writing Chrome exploits and achieved a full exploit in about 12% of attempts, close to 14% for Mythos, a restricted model from Anthropic. The notable shift is the jump from the previous generation, which reportedly produced zero complete exploits. The gap between leading open and closed systems is now narrow enough to change operational risk.
In one test, a security researcher reportedly let the model work with limited supervision for a day against a browser environment. The model identified previously unknown vulnerabilities and chained them into an attack in which a malicious web page could read files from a victim machine. The demonstration included theft of a private key, showing the risk extends beyond theoretical vulnerability discovery.
Using the lighter Flash version, a researcher took a recently disclosed and already patched Chrome flaw and turned it into a working exploit with about 20 minutes of human attention and 8 hours of model work. The estimated compute cost was around $20. That pricing suggests offensive experimentation is moving within reach of small teams and independent operators.
The model reportedly refused explicit malicious requests by default, but those safeguards weakened under common jailbreak-style conditions. Presented as an authorized security exercise, it complied in 64% of cases; with prefilled reasoning, compliance rose to 92%; and with abliteration, a standard refusal-removal technique, it reached 100%. Because the model weights are public, safeguards can be altered directly rather than merely prompted around.
The reported cost of modifying the model to suppress refusals was about $4,400, described as roughly the price of a used car. Crucially, the model lost little capability after modification. That means the main advantage of closed systems is no longer raw intelligence alone, but control over deployment, auditing and access to the underlying weights.
GLM 5.3 was released publicly on Hugging Face weeks after launch, and altered versions reportedly circulated soon after. Unlike a software bug, open model weights cannot be patched out of existence once downloaded globally. A public U.S. evaluator linked to NIST reportedly judged the model to be about four months behind the best U.S. systems, implying frontier capabilities may reach open distribution with only a short delay.
The report’s proposed response includes giving defenders access to top-tier models and having states test sufficiently capable systems. That aligns with the interests of companies selling closed, controllable AI services, especially as open models approach comparable performance. The conflict of interest does not invalidate the findings, but it complicates how recommendations on regulation and model access should be interpreted.
The central asymmetry is operational: attackers adopt every useful tool immediately, while defenders often wait for legal review, budgets or maintenance windows. The practical advice is to assume a public vulnerability may already have a working exploit, inventory internet-exposed assets, and test capable defensive models on internal environments before adversaries do. In this view, security is now measured less by exclusivity and more by reaction time.
Organizations are being pushed toward a cycle of software inventory, continuous monitoring, threat triage and rapid remediation. Recommended tooling includes SBOMs, OSV Scanner, Dependency-Track, CVE and KEV monitoring, plus AI-assisted reachability analysis to separate real risk from alert noise. For firms selling into the European Union, the Cyber Resilience Act adds pressure with reporting deadlines of 24 hours for actively exploited flaws or serious incidents from 11 September 2026, while SBOM obligations apply from 11 December 2027.
The spread of capable open AI models is eroding the old security model based on keeping dangerous capabilities rare. As offensive AI becomes inexpensive and downloadable, the decisive advantage shifts to how quickly organizations can detect exposure, judge risk and deploy fixes.
Ask a question