On September 29, Anthropic announced that it had verified Zhipu AI (Z.ai)'s AI model "GLM-5.3" and confirmed its ability to autonomously construct end-to-end attack code. The company views the fact that GLM-5.3's model weights are publicly available and can be downloaded and used by anyone as problematic.

In an evaluation targeting known vulnerabilities in the V8 engine used by Google Chrome, the model successfully created a series of attack codes in 50 out of 410 attempts. Furthermore, in experiments with researchers, it discovered multiple unknown browser vulnerabilities and constructed attacks that combined them to read files within a device.

Since GLM-5.3 is released as an open-weight model, users can modify its safety features themselves. According to Anthropic, a version of GLM-5.3 with weakened safety features showed a significant decrease in its refusal rate for harmful requests. Third parties reportedly released such modified versions within days of its public release.

Anthropic points out that the availability of AI with advanced cyber capabilities has entered a new phase. However, it also states that the same capabilities can be used by defenders for vulnerability discovery and patching, and calls for strengthened safety measures and third-party evaluations.