Anthropic Says GLM-5.3 Can Build End-to-End Network Exploits
Simple simulated attacks bypassed the model’s safeguards about 64% to 100% of the time, while protected Claude models resisted the same methods.

Anthropic said GLM-5.3 can autonomously develop end-to-end network exploits, raising the security stakes as comparable capabilities spread through open-weight artificial intelligence models.
The model was developed by Zhipu AI, also known outside China as Z.ai. It has capabilities similar to Claude Mythos Preview, an Anthropic model released on a limited basis about five months ago through Project Glasswing.
Anthropic’s Frontier Red Team said trusted defenders used Mythos Preview to identify more than 10,000 vulnerabilities in critical software. Comparable capabilities have since appeared in other models.
In simulated testing, simple techniques bypassed GLM-5.3’s safeguards about 64% to 100% of the time. The same techniques did not cause protected Claude models to perform harmful tasks.
GLM-5.3 is distributed with open weights and lacks meaningful safeguards against misuse, Anthropic said. Open-weight models make their underlying parameters available for others to run or adapt, which can expand access to both defensive and harmful capabilities.
The model’s capabilities also have defensive applications, including helping security teams strengthen vulnerable systems.
The National Institute of Standards and Technology (NIST) assessed GLM-5.3 on Sept. 17 as the strongest open-weight model for cyber capabilities to date. Its aggregate performance on NIST’s cyber benchmarks trailed leading U.S. models by about four months, a conclusion Anthropic said broadly matched its own assessment.
The findings place GLM-5.3 among the most capable openly distributed models for cybersecurity tasks while highlighting the difficulty of applying safeguards consistently across different systems.


