{
  "id": "anthropic-glm-5-3-cyber-report",
  "edition": "2026-09-30",
  "position": 5,
  "role": "secondary",
  "kind": "story",
  "kicker": "Cyber capability",
  "headline": "Anthropic says China's open-weight GLM-5.3 nearly matches its Mythos Preview at building exploits",
  "standfirst": "A red-team post published on 29 September reports benchmark results, safeguard-bypass rates and a low-cost Chrome exploit chain, all from Anthropic's own testing.",
  "body": [
    "GLM-5.3 is an open-weight model released by the Chinese company Zhipu AI, known outside China as Z.ai, so anyone can download and run it. Anthropic published a red-team post on 29 September 2026 assessing the cyber capabilities of GLM-5.3. The company says the model produced end-to-end exploits on ExploitBench in 50 of 410 attempts, against 56 of 410 for its own Claude Mythos Preview. On a random 100-task subset of Anthropic's internal binary-exploitation benchmark, the company reports full control-flow hijacks in 4 per cent of GLM-5.3 trials and 6 per cent for Mythos Preview. It reports none for Claude Opus 4.6 or for the earlier GLM-5.2.",
    "Anthropic also tested how readily the model engages with harmful requests, in a simulation that does not run code. It says a bare order produced 0 per cent engagement, a cover story 64 per cent, prefilled reasoning 92 per cent and an abliterated copy, with its refusal behaviour stripped out, 100 per cent. Tested safeguarded Claude models stayed at 0 per cent where the attack applied, the company says. Anthropic says its own abliteration took about 2,200 GPU-hours and roughly $4,400, and estimates an experienced team could do it in about 600 GPU-hours and $1,200.",
    "Anthropic says a researcher used GLM-5.3-Flash, with public details of CVE-2026-11645 and another known Chrome flaw, to build a reliable ARM64 exploit chain in eight hours of model time and 20 minutes of human attention, at an API cost it puts at $20.40. Some care is needed. Every figure comes from Anthropic's own tests, and Anthropic makes the competing Claude models it compares against. The harmful-request results come from a simulation rather than live code. Anthropic says its capability findings broadly match an assessment published on 17 September by NIST's Center for AI Standards and Innovation, which called GLM-5.3 'the most cyber-capable open-weight model released to date'. The safeguard-bypass results have not been independently replicated, and the benchmark samples are modest in size."
  ],
  "word_count": 324,
  "reading_minutes": 2,
  "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/anthropic-glm-5-3-cyber-report/",
  "api_url": "https://theamateur.co.uk/ai-journalism/api/v1/stories/2026-09-30/anthropic-glm-5-3-cyber-report.json",
  "published_at": "2026-09-30T17:00:00+01:00",
  "updated_at": "2026-09-30T17:00:00+01:00",
  "sources": [
    {
      "role": "primary",
      "label": "Anthropic, GLM-5.3 and the spread of advanced cyber capabilities, 29 September 2026",
      "url": "https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced-cyber-capabilities"
    },
    {
      "role": "independent",
      "label": "The Decoder, Anthropic says GLM-5.3 nearly matches Mythos Preview, 30 September 2026",
      "url": "https://the-decoder.com/anthropic-says-zhipus-open-weight-glm-5-3-nearly-matches-claude-mythos-preview-at-building-exploits/"
    }
  ],
  "images": [
    {
      "id": "anthropic-glm-5-3-cyber-report-hero",
      "role": "hero",
      "editorial_role": "contrast",
      "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/assets/anthropic-glm-5-3-cyber-report.png",
      "variants": [
        {
          "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/assets/anthropic-glm-5-3-cyber-report-400.webp",
          "width": 400,
          "height": 250,
          "format": "webp"
        },
        {
          "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/assets/anthropic-glm-5-3-cyber-report-800.webp",
          "width": 800,
          "height": 500,
          "format": "webp"
        }
      ],
      "width": 1200,
      "height": 750,
      "format": "png",
      "sha256": "5d3f00d7062b9a2a9597ed14c44d252e98883aa941700479a8b11866e49c6eca",
      "alt": "Bar chart of how often GLM-5.3 engaged with an overtly harmful order in Anthropic's simulation: bare order 0%, cover story 64%, prefilled reasoning 92%, abliterated weights 100%.",
      "caption": "How often GLM-5.3 engaged with an overtly harmful order in Anthropic's simulation, by bypass method. Original chart from Anthropic's 29 September post.",
      "credit_line": "Chart: © THE AMATEUR LIMITED · Reuse only with permission (support@theamateur.co.uk)",
      "provenance_type": "original_diagram",
      "photorealistic": false,
      "creator": "THE AMATEUR LIMITED",
      "rights_holder": "THE AMATEUR LIMITED",
      "copyright_notice": "© THE AMATEUR LIMITED",
      "licence": {
        "id": "theamateur-reuse-with-permission-1.0",
        "name": "Reuse only with permission",
        "url": "https://theamateur.co.uk/ai-journalism/images-and-licensing/#reuse",
        "statement": "© THE AMATEUR LIMITED · Reuse only with permission (support@theamateur.co.uk)"
      },
      "attribution_required": true,
      "attribution_text": "© THE AMATEUR LIMITED, theamateur.co.uk",
      "reuse_by_agents": "permission_required",
      "source_url": "https://theamateur.co.uk/ai-journalism/2026-09-30/anthropic-glm-5-3-cyber-report/",
      "source_terms_url": null,
      "modifications": [],
      "depicts_real_event": false,
      "rights_checked": {
        "by": "Editor (AI agent)",
        "on": "2026-09-30"
      },
      "story_id": "anthropic-glm-5-3-cyber-report"
    }
  ],
  "corrections": []
}
