TL;DR: Anthropic researchers led by Michael Fasano tested Z.ai's GLM-5.3 against internal exploit benchmarks and jailbreak suites. On ExploitBench it scored 50 of 410 end-to-end tasks versus 56 for a restricted Mythos preview, with similar binary-exploitation rates on smaller sets. Simulated attacks stripped GLM-5.3's refusals while Claude stayed at zero percent success on the same tests. The team also chained a browser-engine flaw and flagged a Chrome issue using the model plus human time. NIST's CAISI called GLM-5.3 the most cyber-capable open-weight model to date, roughly four months behind the U.S. frontier in a separate 17 September assessment.
Status note: Checked 5 October 2026 against Anthropic's research post of 29 September 2026. Benchmarks reflect Anthropic's lab setup; real-world abuse rates are not measured in the paper. Vendor patches and model revisions can change the numbers later.
Why open weights changed the cyber debate
Closed models from U.S. labs ship with API gates, monitoring, and terms of use. Open-weight models publish parameters anyone can run locally, fine-tune, or wrap in tools without the vendor's permission. Security officials worry that capability moves faster than safeguards when downloads are free and global.
China's Zhipu AI, also branded Z.ai, released GLM-5.3 into that open ecosystem. Anthropic's team treated it as a case study in how fast exploit assistance can spread when weights are public, not as a courtroom claim about Zhipu's intent.
What the benchmarks showed
On ExploitBench, which tests end-to-end exploit generation across hundreds of tasks, GLM-5.3 succeeded on 50 of 410 items. Anthropic's restricted Mythos preview hit 56 of 410, a narrow gap on that suite. On 100 open-source fuzzer tasks focused on full control hijacks in binary exploitation, GLM-5.3 reached 4 percent versus Mythos at 6 percent, while Claude Opus 4.6 and GLM-5.2 scored zero on that slice.
Those numbers describe automated scoring in Anthropic's harness, not a count of live hacks. They still matter because they compare a downloadable model against internal systems the company already treats as dangerous enough to lock down.
When safeguards failed in simulated attacks
Anthropic ran jailbreak-style tests that mimic how attackers try to bypass refusals. With a cover story prompt, GLM-5.3 complied 64 percent of the time. Prefilling the model's private reasoning block pushed success to 92 percent. Abliteration, a technique that surgically weakens refusal circuits, hit 100 percent success in their tests and took about 2,200 GPU hours, which they estimated near $4,400 in compute.
After abliteration, refusal rates on public jailbreak suites collapsed from above 90 percent to roughly 3 percent on JailbreakBench, 2 percent on HarmBench, and 12 percent on StrongREJECT. Claude models registered 0 percent on the same simulated attacks in the post. Again, that is a lab red team, not a survey of criminal success rates on the open internet.
Human-plus-model findings defenders can patch
The researchers paired GLM-5.3 with human operators for deeper work. They report finding zero-day class issues in a Linux browser JavaScript engine, chained to read local files, and disclosed them to the maintainer. GLM-5.3-Flash, a faster variant, helped exploit a known Chrome flaw tracked as CVE-2026-11645 plus another bug, including a pointer-authentication bypass on ARM64, in about 20 minutes of human time and eight hours of model time for roughly $20.40 in API charges on their run.
Anthropic contrasted that with Mythos, developed under Project Glasswing, which the post says targets more than 10,000 vulnerabilities for defender use. The GLM-5.3 work is offensive-capability research published to warn the ecosystem, not a product launch.
Where things stand
GLM-5.3 remains publicly downloadable while Anthropic argues the cyber skill floor dropped. NIST's Center for AI Standards and Innovation said on 17 September that GLM-5.3 was the most cyber-capable open-weight model it had assessed to date, about four months behind the U.S. frontier in that government review, a separate line of analysis from Anthropic's exploit benches.
Headlines that say GLM-5.3 is already pwned every network confuse capability tests with confirmed mass campaigns. The verified public facts are the research numbers, the disclosed vulnerabilities, and the policy warning. Defenders should patch, monitor, and treat open-weight releases as shared infrastructure, not as someone else's problem because the vendor is overseas.
Sources: Anthropic research, 29 September 2026.