Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

Elite AI Hacking Just Went Open-Weight: What Anthropic and NIST Found in China’s GLM-5.3, and 7 Steps to Patch Faster (AI Trends, 30 September 2026)

  1. Home   »  
  2. Elite AI Hacking Just Went Open-Weight: What Anthropic and NIST Found in China’s GLM-5.3, and 7 Steps to Patch Faster (AI Trends, 30 September 2026)

Elite AI Hacking Just Went Open-Weight: What Anthropic and NIST Found in China’s GLM-5.3, and 7 Steps to Patch Faster (AI Trends, 30 September 2026)

September 30, 2026 admincybersecurity

What’s trending in AI on 30 September 2026: the kind of hacking skill AI labs have been keeping behind vetting programs is now something anyone can download. In a report published on 29 September, Anthropic said GLM-5.3, an open-weight model from China’s Z.ai (Zhipu AI), nearly matches its own restricted Claude Mythos Preview at building working software exploits. Two weeks earlier, the US government’s AI testing center at NIST called it “the most cyber-capable open-weight model released to date.” Its safety guardrails can be stripped out for a few thousand dollars of computing time, and unlocked copies were circulating within days of release. This post explains what the two assessments found, where they disagree, and the seven steps businesses should take now that the time from “known bug” to “working attack” is shrinking.

Key takeaways

  • Near-frontier exploit skills, openly available. In Anthropic’s tests GLM-5.3 built working exploits in 50 of 410 attempts, against 56 for Claude Mythos Preview. Earlier models managed none.
  • Cheap and fast. A lighter version turned a known Chrome bug into a working exploit for about $20 in model costs, with around 20 minutes of human attention.
  • Safeguards are optional. Once weights are public, refusals can be removed. Anthropic measured a 100% success rate for that technique.
  • Two views, one conclusion. NIST says GLM-5.3 still trails today’s best US models by about four months. Both agree it is the most capable open model for cyber work, which means your patching clock just got shorter.
Elite AI hacking skills just went open-weightA download arrow dropping model weights onto a laptop, with an open padlock. Text: Anthropic and NIST say China’s GLM-5.3 is the most cyber-capable model anyone can download. Tags: 50 of 410 exploits versus 56 for Claude Mythos Preview; a Chrome exploit for 20.40 dollars; safeguards stripped with 100 percent success.AI TRENDS · 30 SEPTEMBER 2026Elite AI hacking skillsjust went open-weight.Anthropic and NIST: China’s GLM-5.3 is the mostcyber-capable model anyone can download.50/410 exploits vs Mythos 56Chrome exploit for $20.40Safeguards stripped: 100%Z.ai (Zhipu) GLM-5.3 · weights public since 28 Aug.weights$ run exploit[+] heap groom[+] shelldelana.co
A model that can help build exploits is now a download, not an application form.

What GLM-5.3 is, and why this is news

GLM-5.3 is a large language model from Z.ai, the Beijing company formerly known as Zhipu AI. According to NIST’s Center for AI Standards and Innovation (CAISI), it was released on 14 August 2026 and its weights were published for anyone to download on 28 August. That makes it different from the most capable US models. Earlier this month, the leading US labs put their strongest cyber models behind vetting programs, and Anthropic’s Mythos Preview is available only to approved organizations. Open weights can’t be recalled or restricted once they’re out.

We covered the open-weight trend’s cost and licensing side in our open-weight vs closed models guide. This week’s reports are about the other side of that trade: what happens when near-frontier offensive capability becomes a commodity.

What Anthropic found

Anthropic ran GLM-5.3 through the same exploit-development tests it uses for its own models, in sandboxed environments against offline targets. On ExploitBench, GLM-5.3 produced working exploits in 50 of 410 attempts (12%), compared with 56 (14%) for Claude Mythos Preview. On an internal binary-exploitation benchmark it achieved full control-flow hijacks 4% of the time, against 6% for Mythos Preview. Earlier models, including Claude Opus 4.6 and the previous GLM-5.2, scored zero on both.

How close GLM-5.3 gets to Claude Mythos PreviewBar chart from Anthropic’s tests. ExploitBench, 410 attempts: GLM-5.3 succeeded 50 times, 12 percent; Claude Mythos Preview 56 times, 14 percent. Internal binary exploitation benchmark, full control-flow hijacks: GLM-5.3 4 percent, Claude Mythos Preview 6 percent. Earlier models, Claude Opus 4.6 and GLM-5.2: 0 percent.How close GLM-5.3 gets to Claude Mythos PreviewExploit success rates in Anthropic’s tests (sandboxed, offline targets)GLM-5.3 (open weights)Claude Mythos Preview (restricted access)ExploitBench410 attempts12% (50)14% (56)Binary exploitationfull control-flow hijack4%6%Earlier modelsClaude Opus 4.6, GLM-5.20% on both benchmarksNIST’s separate tests put GLM-5.3 about four months behind the best current US models.Source: Anthropic research, 29 Sep 2026 · delana.co
A generation ago, neither lab’s models could do this at all.

Two real-world tests stood out. Paired with a human researcher, GLM-5.3 found several previously unknown vulnerabilities in a browser JavaScript engine within a day and chained them into an exploit that stole SSH keys. And GLM-5.3-Flash, a lighter version, turned a known Chrome vulnerability into a working exploit with about 20 minutes of human attention and eight hours of model time, at roughly $20.40 in API costs. Anthropic says the vulnerabilities it found were disclosed to the software’s maintainers.

Why the safeguards don’t matter much

GLM-5.3 does ship with refusals. Asked directly to help build an exploit, it declined every time in Anthropic’s tests. But with a false cover story it engaged 64% of the time, and with prefilled reasoning 92%. The decisive technique is abliteration: editing the downloaded weights to remove the model’s tendency to refuse. That worked 100% of the time, cut refusal rates from about 95% to single or low double digits on standard jailbreak benchmarks, and left the model’s capabilities largely intact. Anthropic estimates it costs about $4,400 of GPU time on a first attempt and about $1,200 for an experienced team. Abliterated copies of GLM-5.3 were posted publicly within days of its launch.

How easily GLM-5.3’s safeguards fallFour steps, each showing how often GLM-5.3 engaged with exploit-development requests. Asked directly: 0 percent. With a false cover story: 64 percent. With prefilled reasoning: 92 percent. After abliteration, which removes refusals from the weights: 100 percent, at an estimated 1,200 to 4,400 dollars of compute. Abliterated copies appeared online within days of launch.How easily the safeguards fallShare of exploit-development requests GLM-5.3 engaged with, by method0%Asked directly64%False cover story92%Prefilled reasoning100%Abliteration~$1,200–$4,400 computeOnce weights are public, refusals are optional: abliterated copies appeared within days of launch.
Safeguards on downloadable weights are a speed bump. Source: Anthropic.

None of these bypasses worked against safeguarded Claude models, Anthropic says, because those are only served through an API and their weights aren’t public. That is also why its analysis deserves a careful read rather than a headline one.

Anthropic vs NIST: close to the frontier, or four months behind?

NIST’s CAISI published its own assessment on 17 September. It agrees GLM-5.3 is the most cyber-capable open-weight model yet, but says it lags the US frontier by about four months, with a clear gap on every benchmark it ran: 40.4% vs 90.2% on SEC-Bench Pro, 61.1% vs 100% on ExploitBench, 9.4% vs 44.4% on ExploitGym and 7.7% vs 23.2% on OSS-Fuzz.

The two findings aren’t contradictory. They compare different things with different test setups. Anthropic measured GLM-5.3 against Mythos Preview, a model it unveiled about five months ago; NIST compared it with today’s best US systems. The Decoder also points out that Anthropic, which doesn’t release its model weights, has a commercial interest in arguing that closed models are safer, and that its calls for government testing raise regulatory-capture questions. Keep both points in mind. For defenders, the practical conclusion doesn’t depend on who is right about the exact gap: capability that was frontier-only a few months ago is now in anyone’s hands.

From release to warning in seven weeksTimeline. 14 August 2026: Z.ai releases GLM-5.3. 28 August: model weights published for download. Days later: abliterated copies with safeguards removed appear online. 17 September: NIST’s CAISI calls it the most cyber-capable open-weight model to date, about four months behind the US frontier. 29 September: Anthropic reports it nearly matches Claude Mythos Preview at building exploits. Below, two readings: Anthropic compares it with its restricted Mythos Preview model and finds them close; NIST compares it with today’s best US models and finds a clear gap, for example 61 percent versus 100 percent on ExploitBench. Both agree it is the most capable open model for cyber work and that its safeguards are weak.From release to warning in seven weeksGLM-5.3, 202614 AugModelreleased28 AugWeightsdownloadableDays laterUnlocked copiesonline17 SepNIST CAISIassessment29 SepAnthropicreportAnthropic’s readingCompared with its own restrictedMythos Preview model: nearly as goodat building exploits (12% vs 14%)Anthropic sells closed models: note the interestNIST’s readingCompared with today’s best US models:about four months behind(ExploitBench 61% vs 100%)Different benchmark setup and scoringBoth agree: the most cyber-capable open-weight model yet, with safeguards that don’t hold.Sources: NIST CAISI, Anthropic, The Decoder · delana.co
Different yardsticks, same warning for defenders.

The UK AI Security Institute has tracked the same trend, finding the lag between open and closed models shrinking from six to ten months to four to seven months, with open-model safeguards largely ineffective, according to The Decoder.

What this means for your business

  • The exploit clock is shorter. If a model can turn a published browser bug into a working exploit in hours for about $20, the gap between a patch being released and attacks using it narrows. Patch cycles measured in weeks now carry more risk.
  • Attackers don’t need to apply for access. Frontier labs vet who gets their best cyber models; downloadable weights have no vetting. Expect less-skilled groups to attempt more sophisticated attacks, alongside the AI-driven malware already in the wild.
  • Using GLM-5.3 isn’t the same as being attacked by it. Plenty of teams use open models for everyday coding and analysis. The risk to manage internally is unapproved, “uncensored” copies running on company machines, not legitimate use under a policy.
  • Most attacks will still hit old doors. Faster exploits make unpatched systems and weak logins more dangerous, not less. The basics in our SMB AI threats guide still come first.

7 steps to patch faster than AI can exploit

  1. Put browsers on the fast lane. Anthropic’s cheapest demo targeted Chrome. Force automatic browser updates and require restarts within 48 hours of a security release.
  2. Patch by exploitability, not just severity. Put anything on CISA’s Known Exploited Vulnerabilities list and anything internet-facing at the front of the queue, with a days-not-weeks deadline.
  3. Shrink what’s exposed. Inventory internet-facing systems, remove what you don’t need, and put admin panels and remote access behind VPN or zero-trust access with phishing-resistant MFA.
  4. Assume some exploits will land first. Keep endpoint detection and response on every device, limit admin rights, segment critical systems and test that backups restore.
  5. Use AI on defense now. Put AI-assisted code scanning and vulnerability triage to work on your own software. Anthropic’s advice is blunt: “Cyber defenders should use the best available tools.” If you qualify, apply to the labs’ vetted security programs.
  6. Govern model downloads. Write down who may download and run open-weight models, from where, and on which machines. Block unapproved “uncensored” or abliterated models on company devices, and fold this into your shadow AI policy.
  7. Hold vendors to patch deadlines. Ask software and managed-service providers for their time-to-patch commitments and whether they use AI to test their own code. It fits alongside the vendor questions from today’s White House AI Accord post.

Frequently asked questions

What is GLM-5.3?

GLM-5.3 is a large language model from Z.ai, the Chinese AI company formerly called Zhipu AI. It was released on 14 August 2026 and its weights became publicly downloadable on 28 August. NIST’s CAISI calls it the most cyber-capable open-weight model released so far.

How does GLM-5.3 compare with Claude Mythos?

In Anthropic’s tests, GLM-5.3 built working exploits in 50 of 410 ExploitBench attempts, against 56 for Claude Mythos Preview, and scored 4% vs 6% on a binary-exploitation benchmark. NIST’s separate evaluation puts GLM-5.3 about four months behind the best current US models. The difference is mainly in what each compares it with.

What is abliteration?

Abliteration is a technique for editing an open-weight model’s parameters to remove its tendency to refuse harmful requests, without retraining it from scratch. Anthropic found it fully removed GLM-5.3’s refusals on exploit tasks for an estimated $1,200 to $4,400 of computing time, while leaving its capabilities largely intact.

Is it safe to use GLM-5.3 at work?

The cyber findings are about misuse, not about ordinary use. For everyday tasks, the usual open-weight questions apply: where your data goes, how strong the safeguards are for your use case, and what the license allows. Run approved checkpoints under a written policy, and don’t allow unapproved or “uncensored” copies on company devices.

What should small businesses do about AI-built exploits?

Patch faster, especially browsers and anything facing the internet; use phishing-resistant MFA; keep endpoint protection on every device; limit admin rights; and test your backups. Faster exploits mostly punish organizations that are slow to patch known problems.


Sources

  • Anthropic: GLM-5.3 and the spread of advanced cyber capabilities
  • NIST CAISI: Assessment of Z.ai’s GLM-5.3 cyber capabilities
  • The Decoder: GLM-5.3 nearly matches Claude Mythos Preview at building exploits
  • South China Morning Post: Anthropic raises alarm over GLM-5.3’s hacking ability
  • Tech Startups: Top tech news, 30 September 2026

Post navigation

Previous: Your Voice Is Now Your Likeness: Japan’s Landmark AI Voice-Cloning Ruling and 8 Rules Before Your Business Uses a Synthetic Voice (AI Trends, 30 September 2026)

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC