Anthropic has published a new assessment of Zhipu AI’s GLM-5.3, arguing that the open-weight model has crossed an important threshold in cyber capability. The report says GLM-5.3 can autonomously develop end-to-end exploits in some evaluated tasks and that its built-in safeguards were bypassed in simulated tests with relatively simple methods.
The assessment matters because model weights are broadly available. Anthropic contrasts that distribution model with frontier systems that are released with cyber safeguards or restricted to vetted users. The report also notes that capability can aid defenders, including vulnerability discovery, while warning that accessible offensive capability changes the risk equation for organizations operating exposed software.
For security teams, the practical takeaway is not to treat model-driven exploitation as a distant scenario. Continue reducing exposure: prioritize internet-facing assets, maintain asset inventories, patch known flaws promptly, and exercise detection and incident-response paths for exploit attempts. Teams using open-weight models should apply their own access controls, logging, and acceptable-use boundaries rather than relying solely on a model’s embedded refusals.
Source: Anthropic research: GLM-5.3 and the spread of advanced cyber capabilities.
