GLM-5.3: Anyone Can Now Download an AI That Breaks Into Software
Petr Červenka
On this page 7 sections
The short version
- GLM-5.3 is a new AI model from the Chinese company Z.ai. It can find weaknesses in software and write the code to break in through them, nearly as well as Anthropic's most restricted model.
- Anyone can download it for free. Its "I won't help with that" settings are easy to get around: simple tricks worked between 64% and 100% of the time in Anthropic's tests.
- In one test, a smaller version turned a published Chrome security fix into a working attack in about eight hours. At Z.ai's prices, that cost $20.40.
- For WA businesses and agencies, the change is speed and cost. Once a security update comes out, you have less time to install it before someone can attack the gap.
- The defences have not changed. Update quickly, look after the devices nobody watches, protect passwords and keys, and have a plan.
GLM-5.3 is the first AI model anyone can download that can find security holes in software and build working attacks for them. That is the finding of a report published by Anthropic on . This post explains what the report found in plain English, and what it means for AI cyber attacks on WA organisations.
What is GLM-5.3?
GLM-5.3 is the latest AI model from Zhipu AI, a Chinese company known outside China as Z.ai. It is built for writing code and working through long tasks on its own.
It is also an "open-weight" model. That means the whole model can be downloaded and run on your own computers. There is no account to sign up for, and nobody watching how it is used. Claude, for comparison, only runs on Anthropic's own servers, where Anthropic can see and block misuse.
Why Anthropic tested it
Five months before this report, Anthropic announced a model called Claude Mythos Preview. It was the first AI model that could build complete, working attacks on software on its own. Anthropic chose not to release it to the public.
Instead, it gave Mythos only to vetted security teams through a program called Project Glasswing. Those teams found more than 10,000 weaknesses in important software, so they could be fixed before attackers had a tool this good.
Anthropic's report says that head start is now over. GLM-5.3 can do much the same job, and anyone can get it.
The US government's AI testing centre, part of NIST, came to a similar view first. On it called GLM-5.3 "the most cyber-capable open-weight model released to date", about four months behind the best US models.
Z.ai did take some care. According to The Batch, it held the download back for about two weeks of safety testing with security partners. But once a model is out, its maker cannot control what people do with it.
One thing to keep in mind: Anthropic sells a competing product, and runs the restricted program the report says should grow. Its test results are what this post relies on.
What can GLM-5.3 do?
Anthropic ran its tests on sealed-off computers, against targets it set up for the purpose. Nothing real was attacked.
It builds attacks for known flaws
On a standard test of breaking into Chrome's JavaScript engine, GLM-5.3 built a complete working attack in 50 of 410 attempts. Anthropic's restricted Mythos model managed 56 of 410. On Anthropic's own in-house test, GLM-5.3 succeeded 4% of the time against Mythos's 6%. Earlier models from both companies scored zero on that test.
Those rates look low. They do not need to be high. An attacker needs one success, and can keep trying for as long as they can afford.
It finds new holes nobody knew about
A researcher pointed GLM-5.3 at a popular web browser, which Anthropic does not name. Within a day, with limited human attention, the model found several security flaws nobody knew about. It combined them into a web page that could read files off the computer of anyone who visited it. Anthropic's screenshot shows it taking a private login key.
In the same session the model found more flaws in wireless and graphics drivers (the small programs that run your hardware) and in software on network devices. Anthropic has reported the browser flaws to the maker and is reviewing the rest.
It turns public fixes into attacks, fast
When a company like Google releases a security fix, the published details describe the problem it fixes. A researcher gave those details for a recent Chrome flaw to GLM-5.3-Flash, the smaller and less capable version. With very little help, it built a reliable working attack.
It took eight hours of computer time and 20 minutes of a person's attention. At Z.ai's prices, that cost $20.40.
Why are its safety settings a problem?
GLM-5.3 does have safety settings. Ask it plainly to attack a system and it says no. Anthropic tried simple workarounds in a simulated setting where nothing the model wrote was actually run:
| What the tester did | How often GLM-5.3 went along with it |
|---|---|
| Asked directly | 0% |
| Told it that it was part of a security testing exercise | 64% |
| Edited its "thinking" so it looked like it had already agreed | 92% |
| Used a copy with the safety behaviour stripped out | 100% |
Stripped-down copies of GLM-5.3 were posted online within days of release. Anthropic made its own to measure the effect. Its team had never done it before and spent about $4,400 of computer time. It estimates an experienced team could do it for about $1,200.
The stripped copy refused harmful requests only 2% to 12% of the time, down from over 90%. It lost almost none of its skill. The safety comes out and the ability stays.
None of these tricks worked on the Claude models Anthropic tested. That is partly because Claude cannot be downloaded and edited, and users cannot rewrite its "thinking".
What does GLM-5.3 mean for WA organisations?
None of these attacks are new. Criminals have broken into browsers and devices for decades. What has changed is the price. Building an attack like this used to take a skilled specialist. Now it takes a computer, a few hours and about twenty dollars.
Anthropic expects governments and other groups to use models like this to cause real harm. In our view, that means more attempts against more organisations, including small businesses and councils that were never worth a specialist's time.
The biggest risk is the gap between a security update being released and you installing it. During that gap, the update itself tells attackers where to look.
Does the Essential Eight still cover it?
Mostly, yes. WA government agencies work to the Essential Eight at Maturity Level One, and many businesses use it as their baseline. At that level:
- web browsers must be updated within two weeks
- internet-facing services within 48 hours when a flaw is critical or an attack for it already exists
- drivers and device firmware are not required at all until Level Three.
Two weeks is still compliant. But when a working attack can be built in an afternoon, two weeks is a long time. And the drivers where GLM-5.3 found new flaws sit outside Level One entirely.
What should you do now?
- Update browsers within days, not weeks. Turn on automatic updates for Chrome, Edge and the rest. Then check they actually apply: browsers often wait for a restart, and staff rarely restart. Most browsers can force a restart through your device management settings.
- Update the devices nobody looks at. Firewalls, Wi-Fi access points, network storage and printers all run software. Make a list, find out who updates each one and how often, and put it on a schedule. If the answer is "whoever installed it, once", start there.
- Keep passwords and keys out of plain files. The browser attack in the report stole a file off the user's computer. Use a password manager. Turn on multi-factor sign-in everywhere it is offered, so a stolen password or key is not enough on its own.
- Have a plan for the bad day. Know who you would call. Keep backups that are stored offline and that you have actually tested restoring from. Keep a list of every system you have facing the internet, so you know what to check first.
- Ask your software and IT providers two questions. How quickly do they install security updates? And do they use AI tools to check their own code for security holes? Anthropic argues defenders need tools as good as the attackers have. Your providers should already be thinking about this.
If you are not sure where you stand, our free Essential Eight self-assessment takes a few minutes.
Frequently asked questions
Is it safe to use GLM-5.3 in my business?
The report does not cover this, and neither does this post. Using a model like GLM-5.3 raises separate questions about where your data goes and what your procurement rules allow. Get advice before you try it with real data.
Can AI help defend us too?
Yes. Anthropic says vetted security teams can already use its newer Claude Mythos 5.1, and it is working to open access to more defenders. OpenAI runs a similar effort called Patch the Planet. For most organisations, the practical step is to ask your providers whether they use these tools.
Has this happened before?
Not with a model this capable that anyone can download. But the same basics keep coming up. We wrote about AI agents that broke into Hugging Face and the Perth supply chain arrests. Both got in through ordinary gaps: keys and passwords that lived too long, and permissions or updates nobody had checked.
The fixes have not changed. You just get less time to apply them.
If you want help working out which of your systems need attention first, talk to our cyber security consulting team or get in touch.
Photo credits. All images used under the Unsplash License — free for commercial use, attribution appreciated:
- Code on a dark screen — Jakub Żerdzicki
- Rusted padlocks — Felicia Montenegro
Sources
- GLM-5.3 and the spread of advanced cyber capabilities — Anthropic Frontier Red Team, 29 September 2026. All test results in this post unless marked otherwise.
- CAISI's assessment of Z.ai's GLM-5.3 cyber capabilities — NIST, 17 September 2026, as quoted in Anthropic's report.
- GLM-5.3 makes cybersecurity gains — The Batch, 28 August 2026. The delayed download.
- Project Glasswing and its initial update — Anthropic
- Essential Eight patching timeframes — our summary of the ASD maturity model
Was this useful?
Thanks — noted.
Share
Petr Červenka
Petr is the founder and lead developer at Nano Solutions, a Perth-based custom software firm. With over a decade of experience building enterprise platforms for government and private sector clients, he leads delivery of complex projects across Australia.
Connect on LinkedIn