Anthropic flags GLM-5.3 as freely downloadable cyber capability

Anthropic's Frontier Red Team published GLM-5.3 and the spread of advanced cyber capabilities on 29 September 2026. The post assesses Z.ai's GLM-5.3 (Zhipu AI inside China) on autonomous end-to-end cyber exploit development. Anthropic says attackers can bypass its safeguards in simulated tests between 64% and 100% of the time.

On 17 September 2026, NIST's Center for AI Standards and Innovation (CAISI) published CAISI's Assessment of Z.ai's GLM-5.3 Cyber Capabilities. CAISI calls GLM-5.3 "the most cyber-capable open-weight model released to date" and says it lags the U.S. frontier by about four months on CAISI's aggregate cyber measure. Anthropic says its capability findings broadly match CAISI's, and adds a safeguard-bypass analysis.

NIST dates the GLM-5.3 model release to 14 August 2026, with public weights two weeks later. Weights are listed on Hugging Face as zai-org/GLM-5.3.

Z.ai open weights meet Anthropic and NIST assessments

Z.ai released the model and weights. Anyone can download GLM-5.3. Anthropic contrasts that with U.S. frontier cyber-capable models that ship with safeguards or through limited access programs such as Project Glasswing.

Defenders who already track open-weight Chinese models are the immediate audience. See earlier Frontier coverage of Zhipu's ZCode upload apology and China's AI Safety Governance Framework 3.0 agent annex. Model hosts, cloud providers and vulnerability-response teams are next.

CAISI scores plus Anthropic's safeguard bypass rates

CAISI reports GLM-5.3 scores as an agent on four cyber benchmarks. U.S. models were tested with cyber safeguards disabled when applicable.

  • SEC-Bench Pro: CAISI reports 40.4% (74/183) for GLM-5.3, versus 90.2% for the U.S. frontier lead and 27.3% for the PRC frontier lead.
  • ExploitBench: CAISI reports 61.1% (9.8/16) versus 100% for the U.S. frontier lead and 32.2% for the PRC frontier lead.
  • ExploitGym (userspace): CAISI reports 9.4% (47/498) versus 44.4% and 2.6%.
  • CAISI OSS-Fuzz: CAISI reports 7.7% (23/297) versus 23.2% and 2.4%.

Anthropic reports that on its ExploitBench setup, GLM-5.3 developed end-to-end exploits in 50 of 410 attempts, near Claude Mythos Preview at 56 of 410. On an internal binary exploitation set of 100 tasks, Anthropic says GLM-5.3 reached full control-flow hijack in 4% of trials, versus 6% for Mythos Preview. Earlier models including Claude Opus 4.6 and GLM-5.2 scored zero, Anthropic says.

On safeguard strength, Anthropic says direct harmful requests were refused in all simulated trials out of the box. Engagement rose to 64% with a deceptive cover story, 92% with thinking-token prefill, and 100% with an abliterated open-weight copy, Anthropic reports. Anthropic says the same techniques did not get safeguarded Claude models to carry out the harmful tasks it tested. This article does not reproduce those techniques.

Anthropic also describes sandboxed researcher sessions that found previously unknown browser-engine issues, disclosed to the maintainer. It also describes a timed N-day chain exercise on CVE-2026-11645 using GLM-5.3-Flash. Mechanism detail stays in Anthropic's post; operators should read that primary and the NIST write-up for evaluation design. This summary is not a substitute.

Vendor red-team results are not a public exploit catalog

Anthropic's bypass rates come from its simulated tests. CAISI's U.S. frontier comparisons include trusted-access releases with safeguards disabled where applicable, so the gap is not the same as "what an attacker can buy from a U.S. API today."

Neither primary publishes a complete public catalog of the novel flaws Anthropic says it found. Hugging Face listing confirms weights availability. Z.ai's marketing page for GLM-5.3 returned no usable article text when The Frontier fetched it at 02:55 SGT on 30 September 2026.

For nearby UK eval context on agent misuse, see UK AISI's GPT-6 Astra unsanctioned supply-chain findings.

Assume open-weight cyber agents are in adversary hands

Product security and SOC teams should treat GLM-5.3-class open weights as available to both defenders and attackers now. Prioritize patching and monitoring for browser engines, widely fuzzed open-source targets and recently disclosed Chrome issues named in public trackers.

Model hosts and enterprise AI buyers should ask whether any hosted open-weight endpoint offers GLM-5.3 or abliterated variants. Ask what misuse filters still bind after download. Governments and evaluators already have CAISI's 17 September template; Anthropic argues successors need independent safety testing before the next open release.

Do not use this article as an attack guide. Use the NIST and Anthropic primaries for defensive prioritization only.