A Chinese lab's new model is nearly as good at hacking as U.S. AI
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Sarah Grillo/Axios
Chinese open-weight models are closing in on U.S. frontier models' ability to find and exploit security flaws — and they could land in the public's hands more quickly.
Why it matters: Cyber-capable AI models can bring huge gains to both defenders and hackers eager to scale up their operations.
Driving the news: China-based AI lab Z.ai warned Friday that its latest model, GLM-5.3, is so capable at finding and exploiting security flaws that the company will delay the public release of the model weights for two weeks as it tests and strengthens safety and security controls.
- The company specifically trained GLM-5.3 to get better at finding vulnerabilities by letting it practice cyber tasks in controlled environments.
- Z.ai is implementing a tiered access program that only gives selected security partners access to GLM-5.3 in controlled environments.
By the numbers: GLM-5.3 scored 84.5% on CyberGym, a benchmark that tests how well models can find known security vulnerabilities — beating out Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol.
- On ExploitBench, which tests models' ability to reason through and develop exploits for real vulnerabilities, GLM-5.3 trailed only Fable 5 and GPT-5.6 Sol, among the models Z.ai tested.
The big picture: As some U.S. labs slow down model releases over security risks, Chinese labs are forging ahead and fine-tuning their open-weight models to be better at cyber tasks.
- Meanwhile, hackers are experimenting more with AI models. Earlier this week, researchers at Dream found that open-source AI agents were used in an automated cyberattack against Taiwan's government.
Zoom in: Z.ai claims its GLM models have found more than 2,400 security flaws, including over 1,000 that are considered critical and high, according to a new disclosure site released Friday.
- Some of those vulnerabilities were found in the Linux kernel and across widely used VMware and Apache projects.
Between the lines: Z.ai is framing the release of GLM-5.3 as a boon for defenders.
- "An open world cannot have only open attack surfaces," the company wrote on X. "It must also have an open shield."
- Z.ai also announced a new program Friday where open-source maintainers can have a GLM model scan their open repositories for bugs.
The intrigue: At least one of the company's models has already proven useful to defenders: Hugging Face said it used GLM-5.2 to investigate a recent breach involving OpenAI's models after guardrails on U.S. frontier models declined to help.
Yes, but: Once GLM-5.3's weights are public, Z.ai acknowledged in its X post that it won't be able to control how people modify or use the model.
What we're watching: The Trump administration appears to be considering ways it can regulate open-source models as their capabilities start to rival their closed counterparts.
