Research · curated 30 Sep 2026

GLM-5.3 and the spread of advanced cyber capabilities

Coverage timeline

discovered anthropic.com primary 29 Sep 2026simonwillison.net

Single-source research — first reported, latest, and curated coincide.

Why it matters

GLM-5.3's combination of frontier-level autonomous exploit-building and easily removable safeguards lowers the barrier for malicious actors to launch sophisticated cyberattacks, a capability defenders must anticipate proliferating across open-weight models.

Anthropic's Frontier Red Team published an analysis finding that Zhipu AI's GLM-5.3 can autonomously build end-to-end cyber exploits, developing full control-flow hijacks in 4% of trials on an internal binary exploitation benchmark. Because GLM-5.3 is released as open weights with weak safeguards, testers bypassed its safety measures 64–100% of the time using simple techniques such as false cover stories, prefilled reasoning, and abliteration, whereas safeguarded Claude models resisted the same attacks.