Daily Podcast full article
Open GLM-5.3 Has Nearly Caught Anthropic’s Secret Mythos
A Chinese open-weight model is now close enough to Anthropic’s restricted Mythos Preview on Chrome exploit benchmarks that the story is no longer just about AI performance. It is about who gets access, how fragile model guardrails become once weights are public, and why defenders must assume automated exploit development is moving from elite labs into ordinary infrastructure risk.
The threshold that changed the argument
The headline is simple, and uncomfortable: GLM-5.3, an open-weight model from Zhipu AI, is now being described as close to Anthropic’s restricted Claude Mythos Preview on a benchmark for writing working browser exploits. DigiTimes reported on October 5 that Anthropic had flagged GLM-5.3 for approaching Mythos Preview on exploit development while lacking sufficient safety protections . SparkOne’s October 4 breakdown gives the numbers behind that alarm: GLM-5.3 completed 50 of 410 ExploitBench attempts, while Claude Mythos Preview completed 56 of 410 .
That is not parity in every sense. It is not proof that GLM-5.3 is “better” than Anthropic’s strongest cyber model. It is not a live-attack report. The tests were run in controlled, isolated settings, and several fresh write-ups emphasize that the underlying measurements are Anthropic’s assessment of a competitor’s model . But the gap is small enough to change the practical question. The question is no longer whether open-weight models can eventually reach restricted cyber capability. The question is what defenders do now that one has reached the neighborhood.
What was actually measured
ExploitBench focuses on known vulnerabilities in V8, the JavaScript engine used by Chrome. The benchmark asks whether a model can move from a known bug to a complete working exploit, not merely identify a weakness or produce a vague report . In that setting, GLM-5.3 reached 50 successful attempts out of 410, compared with 56 for Mythos Preview . PodParadise’s October 4 AI Engineering Briefing summarized the same comparison as 50 of 410 for GLM-5.3 versus 56 for the restricted Mythos Preview, and framed the operational takeaway as shorter patch windows and deeper defense .
A second Anthropic test, described in the October 4 SparkOne analysis and ToKnow’s October 4 report, used 100 binary-exploitation tasks based on open-source projects and awarded credit only for full control-flow hijack . GLM-5.3 reached 4 percent on that benchmark, while Mythos Preview reached 6 percent . Older models such as Claude Opus 4.6 and GLM-5.2 reportedly scored zero on that second test, which is why the result is being treated as a threshold rather than a routine benchmark fluctuation .
The most important nuance is that the Claude comparison was not ordinary consumer access. These are restricted or safeguarded systems tested under special conditions, while GLM-5.3’s weights are available for download and modification . That access difference is the center of the story.
Open weights turn safeguards into settings
The technical point is blunt: if users can download model weights, they can also try to alter the model’s refusal behavior. In Anthropic’s simulations, GLM-5.3 refused plain malicious cyber requests, but its behavior changed sharply under bypass conditions reported by multiple fresh sources . A false red-team cover story produced engagement 64 percent of the time, while prefilled reasoning raised that to 92 percent . Weight modification, often called abliteration, reportedly pushed engagement to 100 percent in the simulated test .
The cost figures are also part of the shock. ToKnow reported that Anthropic’s team used about 2,200 GPU hours, roughly $4,400 of compute, to remove much of the refusal behavior, and that Anthropic estimated an experienced team might do it for about $1,200 . SparkOne reports the same order of magnitude and notes that the resulting refusal rate fell from above 90 percent to between 2 and 12 percent, depending on the benchmark . Wasteland’s October 5 weekly brief compressed the implication: about $4,400 of compute removed refusals, and a smaller version of the model built a Chrome exploit chain for $20.40 .
That does not mean every teenager with a laptop can now run frontier cyber operations. SparkOne notes that GLM-5.3 is not a casual laptop model and that the hardware bar remains meaningful . But the access model has changed from “apply to a controlled program” to “obtain enough compute.” For enterprise security, that is a different risk category.
Why the Chrome detail matters
The Chrome angle is not incidental. Browser engines are among the most valuable targets in software security because they sit between untrusted web content and a user’s machine. A model that can reliably assist with end-to-end exploit construction against browser-engine bugs does not merely improve bug triage; it compresses the time between disclosure, proof of concept, and weaponization.
The GLM-5.3 reporting includes a qualitative example in which a researcher-guided session found unknown flaws in a browser JavaScript engine and chained them into a webpage capable of reading files from a visitor’s computer in a sandboxed setting . Another reported run used GLM-5.3-Flash, the smaller variant, to build a working exploit chain for a known Chrome vulnerability with about 20 minutes of human attention and eight hours of model work . ToKnow and Wasteland both repeat the estimated token cost of $20.40 for that smaller-model run .
This is precisely why the defensive lesson is not “panic.” It is “remove latency.” Patch prioritization, asset discovery, exploitability scoring, and detection engineering need to happen faster than the new economics of exploit generation. Wasteland’s October 5 issue puts the broader security lesson plainly: treating a patch ticket as finished when a patch is installed is no longer enough if attackers may already have arrived, stolen secrets, or automated the next step .
The business conflict is real, but it does not erase the signal
Anthropic is not a neutral observer. It competes with Zhipu AI, keeps its most sensitive cyber-capable models behind controlled access, and has every incentive to argue that closed access is safer. SparkOne explicitly warns readers not to ignore the commercial convenience of Anthropic’s argument . Wasteland likewise notes that the GLM-5.3 numbers are Anthropic’s evaluation of a competitor and have not been independently replicated .
That caveat matters. Benchmark harnesses shape results. “Complete exploit per attempt” is not the same as partial-credit scoring. A controlled sandbox is not the public internet. A model’s willingness to engage with a simulated malicious task is not the same as a confirmed real-world compromise.
But the caveat does not make the numbers harmless. Multiple fresh summaries converge on the same practical interpretation: GLM-5.3 is close enough to Mythos Preview on these exploit tasks, and open enough in deployment, that defenders should no longer assume the strongest offensive AI capability is contained inside a few Western labs . Even if Anthropic’s framing is self-interested, the access asymmetry is real.
What defenders should do next
The defensive answer is not to ban every open model. Open-weight systems are also useful for defenders, researchers, auditors, and organizations that need local control. But the GLM-5.3 episode makes model governance inseparable from cyber operations.
First, security teams should treat AI-assisted exploit development as part of ordinary threat modeling, not as a speculative future category. Second, patch management should shift from calendar-based remediation to exploitability-based response, with special urgency for internet-facing services, browser-adjacent technologies, identity systems, and anything with public proof-of-concept code. Third, organizations running local or self-hosted models need internal controls that do not rely on the model’s own refusal behavior: identity, logging, tool permissions, egress limits, and human approval for dangerous actions.
The uncomfortable lesson is that safety cannot live only inside the model. Once weights are public, refusals become modifiable. Once exploit generation becomes cheaper, the response window shrinks. And once a model like GLM-5.3 comes within striking distance of a restricted system like Mythos Preview, the old reassurance — that the dangerous capability is locked away — no longer holds.
The story is not that Skynet has arrived. It is that the economics of offensive automation just became less theoretical. For defenders, that is already enough.
Sources from the last 72 hours
- [1]Z.ai GLM-5.3 security draws scrutiny as Anthropic flags weak defensesOct 5, 2026, 3:23 AM
- [2]Open weights, no brakes: what GLM-5.3 says about running models yourselfOct 4, 2026, 2:00 AM
- [3]The Patch Is No Longer the Fix, Sep 29 to Oct 5, 2026 — Wasteland № 031Oct 5, 2026, 2:30 PM
- [4]Anthropic’s Red Team: An Open-Weight AI Model That Builds Cyber ExploitsOct 4, 2026, 2:00 AM
- [5]GLM-5.3 exploits Chrome, tokens up 10x — AI News Oct 4Oct 4, 2026, 2:00 AM
AI-generated article based on recent web research, then preserved as a dated editorial snapshot.

Comments
Be the first to comment.