Anthropic says open GLM-5.3 builds exploits nearly as well as Mythos

Illustration for the GLM-5.3 open-weight exploits story

Anthropic says a Chinese AI model anyone can download now builds working cyber exploits almost as well as Anthropic’s own restricted Mythos.

What Anthropic measured

In a report published September 29, 2026, Anthropic tested GLM-5.3, an open-weight model from Zhipu AI (Z.ai). On ExploitBench, built on known bugs in Chrome’s V8 engine, it produced end-to-end exploits in 50 of 410 attempts. Claude Mythos Preview, which Anthropic released only in a limited way, to trusted defenders through Project Glasswing, managed 56 of 410.

In a session with a researcher that lasted about a day, GLM-5.3 found several previously unknown bugs in a popular browser’s JavaScript engine and chained them into a web page that reads files from the visitor’s computer.

Its safeguards refused direct malicious requests in Anthropic’s simulation. Telling it that it was a red-team agent got it to engage 64% of the time, prefilling its reasoning raised that to 92%, and a copy with its refusals stripped out engaged 100% of the time. NIST’s AI center had already called GLM-5.3 “the most cyber-capable open-weight model released to date.”

Why open weights change the math

In August, Z.ai held back the weights for about two weeks, citing cybersecurity risk, and gave only vetted security partners access in that window. The weights are now public, and Anthropic’s argument is that exploit-building ability is no longer something only a few labs can gate: anyone who downloads the model can remove its refusals.

Anthropic, a direct competitor that sells its own models, proposes getting strong models to more defenders faster. The report is also a competitor’s assessment, which makes NIST’s independent evaluation the more neutral reference point for the capability claim.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.