Anthropic Gives Free Advertising to GLM-5.3, Zhipu Surges Over 2% Intraday
律动BlockBeats|9月 30, 2026 04:10
Beating AI News Flash: Anthropic released a cybersecurity evaluation of GLM-5.3, originally intended to warn that open-weight models might lower the threshold for cyberattacks. However, the test results inadvertently served as a strong third-party endorsement for GLM-5.3: it can autonomously execute complex exploitations, with some capabilities approaching Anthropic's own Claude Mythos Preview. Zhipu's stock price surged over 2% intraday today.
On ExploitBench, GLM-5.3 successfully completed end-to-end exploitations in 50 out of 410 attempts, compared to 56 for Claude Mythos Preview. Claude Opus 4.6, GLM-5.2, Kimi K3, and DeepSeek-V4.1-Flash all scored close to zero in the same test. Anthropic stated that GLM-5.3's exploitation capabilities have crossed a significant threshold. Researchers tasked GLM-5.3 with inspecting a mainstream browser in a sandbox environment, where it discovered multiple previously unknown vulnerabilities within a day and chained several 0-days into a complete attack sequence. The final malicious webpage generated could escape the browser sandbox and directly access any file on the computer, including SSH private keys. Even the smaller GLM-5.3-Flash was able to turn publicly disclosed Chrome vulnerabilities into usable attack chains. The entire process required only about 20 minutes of human intervention, with the model running autonomously for 8 hours. Based on Zhipu's API pricing, the cost was just $20.40.
Anthropic's criticism of GLM-5.3 primarily focuses on its security restrictions. While GLM-5.3 would initially reject direct malicious requests, it continued execution in 64% of tests when presented with a fake "red team testing" context; this increased to 92% when preloaded with model reasoning content, and reached 100% when open weights were directly modified to remove rejection mechanisms. Anthropic believes that open weights allow attackers to bypass these security restrictions entirely.
This report was originally intended to demonstrate how dangerous GLM-5.3 is, but its dissemination has had the unintended effect of resembling a performance advertisement written by a competitor. The U.S. NIST previously reached similar conclusions, stating that GLM-5.3 is currently the most capable open-weight model in cybersecurity, though its overall capabilities still lag behind cutting-edge U.S. models by approximately four months. [Original Link]
Share To
HotFlash
APP
X
Telegram
CopyLink