What’s trending in AI on 30 September 2026: the kind of hacking skill AI labs have been keeping behind vetting programs is now something anyone can download. In a report published on 29 September, Anthropic said GLM-5.3, an open-weight model from China’s Z.ai (Zhipu AI), nearly matches its own restricted Claude Mythos Preview at building working software exploits. Two weeks earlier, the US government’s AI testing center at NIST called it “the most cyber-capable open-weight model released to date.” Its safety guardrails can be stripped out for a few thousand dollars of computing time, and unlocked copies were circulating within days of release. This post explains what the two assessments found, where they disagree, and the seven steps businesses should take now that the time from “known bug” to “working attack” is shrinking.
Key takeaways
- Near-frontier exploit skills, openly available. In Anthropic’s tests GLM-5.3 built working exploits in 50 of 410 attempts, against 56 for Claude Mythos Preview. Earlier models managed none.
- Cheap and fast. A lighter version turned a known Chrome bug into a working exploit for about $20 in model costs, with around 20 minutes of human attention.
- Safeguards are optional. Once weights are public, refusals can be removed. Anthropic measured a 100% success rate for that technique.
- Two views, one conclusion. NIST says GLM-5.3 still trails today’s best US models by about four months. Both agree it is the most capable open model for cyber work, which means your patching clock just got shorter.
What GLM-5.3 is, and why this is news
GLM-5.3 is a large language model from Z.ai, the Beijing company formerly known as Zhipu AI. According to NIST’s Center for AI Standards and Innovation (CAISI), it was released on 14 August 2026 and its weights were published for anyone to download on 28 August. That makes it different from the most capable US models. Earlier this month, the leading US labs put their strongest cyber models behind vetting programs, and Anthropic’s Mythos Preview is available only to approved organizations. Open weights can’t be recalled or restricted once they’re out.
We covered the open-weight trend’s cost and licensing side in our open-weight vs closed models guide. This week’s reports are about the other side of that trade: what happens when near-frontier offensive capability becomes a commodity.
What Anthropic found
Anthropic ran GLM-5.3 through the same exploit-development tests it uses for its own models, in sandboxed environments against offline targets. On ExploitBench, GLM-5.3 produced working exploits in 50 of 410 attempts (12%), compared with 56 (14%) for Claude Mythos Preview. On an internal binary-exploitation benchmark it achieved full control-flow hijacks 4% of the time, against 6% for Mythos Preview. Earlier models, including Claude Opus 4.6 and the previous GLM-5.2, scored zero on both.
Two real-world tests stood out. Paired with a human researcher, GLM-5.3 found several previously unknown vulnerabilities in a browser JavaScript engine within a day and chained them into an exploit that stole SSH keys. And GLM-5.3-Flash, a lighter version, turned a known Chrome vulnerability into a working exploit with about 20 minutes of human attention and eight hours of model time, at roughly $20.40 in API costs. Anthropic says the vulnerabilities it found were disclosed to the software’s maintainers.
Why the safeguards don’t matter much
GLM-5.3 does ship with refusals. Asked directly to help build an exploit, it declined every time in Anthropic’s tests. But with a false cover story it engaged 64% of the time, and with prefilled reasoning 92%. The decisive technique is abliteration: editing the downloaded weights to remove the model’s tendency to refuse. That worked 100% of the time, cut refusal rates from about 95% to single or low double digits on standard jailbreak benchmarks, and left the model’s capabilities largely intact. Anthropic estimates it costs about $4,400 of GPU time on a first attempt and about $1,200 for an experienced team. Abliterated copies of GLM-5.3 were posted publicly within days of its launch.
None of these bypasses worked against safeguarded Claude models, Anthropic says, because those are only served through an API and their weights aren’t public. That is also why its analysis deserves a careful read rather than a headline one.
Anthropic vs NIST: close to the frontier, or four months behind?
NIST’s CAISI published its own assessment on 17 September. It agrees GLM-5.3 is the most cyber-capable open-weight model yet, but says it lags the US frontier by about four months, with a clear gap on every benchmark it ran: 40.4% vs 90.2% on SEC-Bench Pro, 61.1% vs 100% on ExploitBench, 9.4% vs 44.4% on ExploitGym and 7.7% vs 23.2% on OSS-Fuzz.
The two findings aren’t contradictory. They compare different things with different test setups. Anthropic measured GLM-5.3 against Mythos Preview, a model it unveiled about five months ago; NIST compared it with today’s best US systems. The Decoder also points out that Anthropic, which doesn’t release its model weights, has a commercial interest in arguing that closed models are safer, and that its calls for government testing raise regulatory-capture questions. Keep both points in mind. For defenders, the practical conclusion doesn’t depend on who is right about the exact gap: capability that was frontier-only a few months ago is now in anyone’s hands.
The UK AI Security Institute has tracked the same trend, finding the lag between open and closed models shrinking from six to ten months to four to seven months, with open-model safeguards largely ineffective, according to The Decoder.
What this means for your business
- The exploit clock is shorter. If a model can turn a published browser bug into a working exploit in hours for about $20, the gap between a patch being released and attacks using it narrows. Patch cycles measured in weeks now carry more risk.
- Attackers don’t need to apply for access. Frontier labs vet who gets their best cyber models; downloadable weights have no vetting. Expect less-skilled groups to attempt more sophisticated attacks, alongside the AI-driven malware already in the wild.
- Using GLM-5.3 isn’t the same as being attacked by it. Plenty of teams use open models for everyday coding and analysis. The risk to manage internally is unapproved, “uncensored” copies running on company machines, not legitimate use under a policy.
- Most attacks will still hit old doors. Faster exploits make unpatched systems and weak logins more dangerous, not less. The basics in our SMB AI threats guide still come first.
7 steps to patch faster than AI can exploit
- Put browsers on the fast lane. Anthropic’s cheapest demo targeted Chrome. Force automatic browser updates and require restarts within 48 hours of a security release.
- Patch by exploitability, not just severity. Put anything on CISA’s Known Exploited Vulnerabilities list and anything internet-facing at the front of the queue, with a days-not-weeks deadline.
- Shrink what’s exposed. Inventory internet-facing systems, remove what you don’t need, and put admin panels and remote access behind VPN or zero-trust access with phishing-resistant MFA.
- Assume some exploits will land first. Keep endpoint detection and response on every device, limit admin rights, segment critical systems and test that backups restore.
- Use AI on defense now. Put AI-assisted code scanning and vulnerability triage to work on your own software. Anthropic’s advice is blunt: “Cyber defenders should use the best available tools.” If you qualify, apply to the labs’ vetted security programs.
- Govern model downloads. Write down who may download and run open-weight models, from where, and on which machines. Block unapproved “uncensored” or abliterated models on company devices, and fold this into your shadow AI policy.
- Hold vendors to patch deadlines. Ask software and managed-service providers for their time-to-patch commitments and whether they use AI to test their own code. It fits alongside the vendor questions from today’s White House AI Accord post.
Frequently asked questions
What is GLM-5.3?
GLM-5.3 is a large language model from Z.ai, the Chinese AI company formerly called Zhipu AI. It was released on 14 August 2026 and its weights became publicly downloadable on 28 August. NIST’s CAISI calls it the most cyber-capable open-weight model released so far.
How does GLM-5.3 compare with Claude Mythos?
In Anthropic’s tests, GLM-5.3 built working exploits in 50 of 410 ExploitBench attempts, against 56 for Claude Mythos Preview, and scored 4% vs 6% on a binary-exploitation benchmark. NIST’s separate evaluation puts GLM-5.3 about four months behind the best current US models. The difference is mainly in what each compares it with.
What is abliteration?
Abliteration is a technique for editing an open-weight model’s parameters to remove its tendency to refuse harmful requests, without retraining it from scratch. Anthropic found it fully removed GLM-5.3’s refusals on exploit tasks for an estimated $1,200 to $4,400 of computing time, while leaving its capabilities largely intact.
Is it safe to use GLM-5.3 at work?
The cyber findings are about misuse, not about ordinary use. For everyday tasks, the usual open-weight questions apply: where your data goes, how strong the safeguards are for your use case, and what the license allows. Run approved checkpoints under a written policy, and don’t allow unapproved or “uncensored” copies on company devices.
What should small businesses do about AI-built exploits?
Patch faster, especially browsers and anything facing the internet; use phishing-resistant MFA; keep endpoint protection on every device; limit admin rights; and test your backups. Faster exploits mostly punish organizations that are slow to patch known problems.
Sources
- Anthropic: GLM-5.3 and the spread of advanced cyber capabilities
- NIST CAISI: Assessment of Z.ai’s GLM-5.3 cyber capabilities
- The Decoder: GLM-5.3 nearly matches Claude Mythos Preview at building exploits
- South China Morning Post: Anthropic raises alarm over GLM-5.3’s hacking ability
- Tech Startups: Top tech news, 30 September 2026
