Anthropic says Zhipu’s open-weight GLM-5.3 nearly matches Claude Mythos Preview at building exploits
What happened
Anthropic reported that Zhipu’s open-weight language model GLM-5.3 produces cyber exploits almost as effectively as Anthropic’s own Claude Mythos Preview. The smaller Flash version of GLM-5.3 managed to design a reliable Chrome attack at just $20.40 using Zhipu’s public API pricing. The model’s security measures can be easily removed, and unlocked versions are already circulating outside controlled environments. Anthropic’s claims are supported by the US agency CAISI, which independently confirms the exploit-building capability.
The risk
This exposes a new tier of accessible hacking automation by lowering barriers to exploit creation. Open-weight and smaller AI models capable of building working cyberattacks for under $25 amplify the risk of hostile actors developing exploits rapidly and cheaply. The fact that Zhipu’s safeguards are fragile means attackers can strip protections and distribute unrestricted versions. This weakens defenses not only for targeted software but also for AI governance frameworks that rely on hard-coded restrictions to prevent misuse.
Why it matters
For security teams and operators, exploit-building AI models that are easy to unlock shift the threat landscape sharply. Cost-effective, widely available models that almost match leading AI exploit proficiency pressure defenders to accelerate patching cycles and threat monitoring. It also raises stakes for AI model providers who must improve safety engineering beyond simple content filters or guardrails. For policy makers and regulators, this development demands urgent attention to AI misuse risks at scale and new approaches to security controls in open AI models.
Who should pay attention
Cybersecurity teams need to recognize these AI models as a direct enabler of exploit innovation, requiring adapted monitoring and response tactics. AI developers and platform operators must reconsider how to safeguard open-weight and smaller models, or risk weaponization. Investors and business leaders in tech should factor increased attack velocity and AI misuse risks into their risk management and resilience planning. Government agencies involved in cyber defense and AI oversight should track this dynamic closely.
What to watch next
Watch for rapid improvements in exploit-building AI models and the spread of unlocked versions. Expect heightened pressure on AI companies to strengthen built-in safety measures and for regulators to impose stricter controls. Monitoring how defenders adapt to cost-effective automated exploit creation will be key—will detection and patching keep pace, or do these models accelerate attack sophistication beyond current defenses?
AI Quick Briefs Editorial Desk