New Chinese AI Models Challenge Cyber Defenses

Two new Chinese AI models can find software vulnerabilities faster and cheaper than most defenders can patch them.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
An advanced computer screen displaying a complex AI algorithm in a darkened cybersecurity operations center
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Zhipu AI released GLM 5.2 on 13 June 2026, which testing found outperforms some U.S. Models on bug-finding benchmarks at $0.17 per vulnerability.
  • 360 Security Technology followed two weeks later with Tulongfeng, which its founder says has already found more than 3,400 vulnerabilities.
  • GLM 5.2 can run on local hardware, giving defenders in operational technology and critical infrastructure environments a data-sovereignty option.
  • Testing by Semgrep gave GLM 5.2 a 39% F1 score, the highest of any standard model in that evaluation.

Chinese companies have released two AI models in the past month that push their vulnerability-discovery capabilities into territory that worries some security teams. On 13 June 2026, Zhipu AI released GLM 5.2, an open-weight model (one that can be installed on private hardware rather than accessed through a cloud service). Testing found it outperforms certain U.S. Models on bug-finding benchmarks and costs $0.17 per vulnerability found. Two weeks on, 360 Security Technology released Tulongfeng, also known as Dragon Saber, a security tool whose founder described it as China's answer to Mythos, claiming it had surfaced more than 3,400 vulnerabilities, according to Reuters.

Our report on China-linked intrusions into Southeast Asian utilities from 3 July 2026 showed offensive capability moving fast; these models suggest the discovery pipeline behind those operations is accelerating too.

Chris Inglis, former U.S. National Cyber Director and a strategic adviser at ransomware-defence firm Halcyon, says the benchmark results are a signal for defenders, not just a headline. "Commodity models now can run circles around defenses," he told Dark Reading, "and so defenses need to get serious about knowing their architecture, prioritizing the weaknesses within that architecture, and, in rapid priority order, ruthlessly patch and fix your configurations."

Attackers are already moving. In April 2026, the Cloud Security Alliance warned that frontier models, most notably Mythos, could trigger an "AI vulnerability storm." In May 2026, Google disclosed the first confirmed AI-created exploit observed in active use. Researchers have noted that even patch-release notes alone can enable exploitation within three hours on average.

Should customers be worried?

Yes, though the more precise question is whether they know their own exposure. Inglis argues that capable AI can already clean out two of the three categories of security debt most organisations carry: known but unpatched vulnerabilities, and unknown but easily discoverable ones. Only the third category, zero-days built on complex attack chains, still requires frontier-class models.

For defenders, GLM 5.2's open-weight design is practically useful. John Gallagher, vice president at IoT cyber-hygiene provider Viakoo, told Dark Reading that organisations in operational technology and critical infrastructure benefit from models they can run internally, sidestepping the data-leakage risk of sending traffic to cloud APIs.

Semgrep's testing gave GLM 5.2 a 39% F1 score, the strongest result among standard models evaluated. Margaret Cunningham, vice president of security and AI strategy at Darktrace, told Dark Reading that where a model comes from matters less than whether security teams can actually embed it in their operations. "Most organizations still have work to do around visibility, workflows, governance, and decision-making," she said. "Those factors will determine defensive effectiveness long before marginal differences between leading models."

That's the part worth watching: not the benchmark race, but whether defenders close their patch backlog before the models do it for the other side.

© 2026 Threat Vectr