Zhipu's GLM-5.3 AI Model: A Double-Edged Sword in Cybersecurity

Zhipu's new AI model excels at finding security flaws but raises concerns about misuse.

ThreatVectr Newsdesk· 3 min read
AI-driven cyber operations visual, depicting autonomous systems in a digital landscape
Share

Key points

  • Chinese AI developer Zhipu launched GLM-5.3 on October 5.
  • The model identified 2,436 vulnerabilities in real-world code.
  • GLM-5.3's effectiveness in finding flaws outpaces its ability to exploit them fully.

What makes GLM-5.3 stand out?

Zhipu's new AI model, GLM-5.3, is impressively good at finding software flaws. The company says it ranks just behind the best in the world for spotting vulnerabilities, which are weaknesses in software that hackers can use to break in. GLM-5.3 scored 84.5% on a test called CyberGym, slightly ahead of rivals like Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol. However, it isn't as good at actually exploiting, or using, these flaws to break into systems as its competitors. On another test, ExploitBench, it scored 54.4%, while the others scored around 76% to 78%.

Why does this matter to ordinary people?

Zhipu tested its model on real-world projects and found 2,436 vulnerabilities across 269 projects, which included critical systems like operating systems and web applications. They found that some of these vulnerabilities had been around for decades, with the oldest dating back to 1981. This means there's a lot of old software out there that could be easily broken into unless it gets fixed. If you use older software or systems, it might be wise to update them.

Metric GLM-5.3 Mythos 5 GPT-5.6 Sol
CyberGym Score 84.5% 83.8% 83.6%
ExploitBench Score 54.4% 78% 76.5%
Vulnerabilities Found 2,436 - -

How did GLM-5.3 become so capable?

The model evolved from its predecessor, GLM-5.2, through a process called post-training. This involves using more complex and realistic scenarios to teach the model. As the training environments got more challenging, the model improved faster than Zhipu expected. It even completed 105 tasks in two hours, compared to just 29 by the older version.

What are the risks?

While models like GLM-5.3 can help find and fix software issues faster, they also make it easier for people with bad intentions to find ways to exploit these flaws. Once Zhipu releases the model's weights, which are settings that determine how it works, anyone could potentially use it to find vulnerabilities. According to Neil Shah from Counterpoint Research, this ability to find flaws quickly means companies need to be prepared to fix issues just as fast.

The article first appeared on CSO Online.

Common questions

How can companies protect themselves?

Companies should regularly update their software and train their staff to recognize security threats. This helps them stay ahead of potential attacks.

Is my personal data at risk?

If a company you use is running outdated software, your data could be at risk from vulnerabilities like those GLM-5.3 found. It's important to use services that prioritize security updates.

© 2026 Threat Vectr