Z.ai Ships GLM-5.3 With Cyber Powers It Didn't Plan

Z.ai's GLM-5.3 hits 84.5% on CyberGym vulnerability detection, beating Claude Mythos 5 and GPT-5.6 Sol, with weights coming after a two-week safety-hardening pause.

Z.ai Ships GLM-5.3 With Cyber Powers It Didn't Plan

Beijing AI lab Z.ai (formerly Zhipu AI) today released GLM-5.3, an open-weights foundation model that keeps GLM-5.2's base architecture but scales up post-training on long-horizon work environments. The company says the model tops every rival on cybersecurity benchmarks and matches frontier US models on complex coding — and that its offensive-security capabilities grew faster than Z.ai anticipated.

84.5% On CyberGym, Ahead Of Mythos 5 And GPT-5.6 Sol

On CyberGym, which tests whether a model can identify and validate vulnerabilities from white-box source code, GLM-5.3 scores 84.5%, up from GLM-5.2's 77.2% and ahead of every comparator including Anthropic's Claude Mythos 5 (83.8%) and OpenAI's GPT-5.6 Sol (83.6%). On ExploitBench, which demands deeper exploitation reasoning, it more than doubles GLM-5.2 to 54.4%. On ExploitGym it finishes 105 tasks within two hours and 130 in six — against 29 and 39 for its predecessor.

Emergent Exploit Chains, Then A Two-Week Pause

Z.ai said it introduced vulnerability data during post-training expecting incremental gains, but the model began reasoning across multi-stage exploitation chains rather than isolated bug-finding. Working with Chinese security teams, GLM-5.3 has already surfaced 2,436 vulnerabilities across 269 open-source projects since GLM-5.2, including 1,097 critical or high severity findings — the oldest introduced in 1981. The weights themselves will ship in roughly two weeks, after a safety-evaluation and hardening cycle.

Z.ai Security Disclosure Ledger logo

Coding And Long-Horizon Task Gains

On the private Z.ai Code Bench, the company reports a 50% jump over GLM-5.2 and outscores Claude Opus 4.8 at comparable effort. On public suites, GLM-5.3 still trails GPT-5.6 Sol and Claude Fable 5 on Terminal-Bench 3.0 and DeepSWE. Related: OpenAI's GPT-5.6-Cyber launch.

Reporting based on coverage from Unite.AI, South China Morning Post and Z.ai's official announcement.

Category: Cyber Security

Tags: Open Source AI AI Models Cybersecurity China AI Foundation Models

Related Articles