Anthropic claims Zhipu GLM-5.3 has Mythos-class hacking abilities
Anthropic reported on 3 October that Zhipu AI's GLM-5.3 model can generate malicious exploits with capabilities comparable to its own unreleased Mythos model, citing benchmark tests where GLM-5.3 successfully developed end-to-end Chrome exploits in 50 out of 410 runs.

On 3 October, Anthropic released a red teaming report asserting that a popular Chinese open-weight model possesses security vulnerabilities that allow it to function as a sophisticated cyberattack tool. The target of these allegations is Zhipu AI's GLM-5.3, which Anthropic claims can automate exploits with an efficiency level similar to its own unreleased, high-security model known as Mythos. This claim lands at a moment of heightened scrutiny regarding the safety of open-weight AI systems, particularly those developed outside the United States.
The Register noted that the performance gap is minimal, suggesting that open-weight models are closing the capability distance with closed, restricted frontier models.
According to The Register, the report details how GLM-5.3 performed in Anthropic's internal benchmarks, specifically Exploitbench, a sandboxed environment designed to test an AI's ability to develop exploits for Google Chrome. In this specific test, GLM-5.3 generated 50 successful end-to-end exploits out of 410 runs. By comparison, Anthropic's own Mythos model, which is not available to the general public, achieved 56 successful exploits in the same number of attempts. The Register noted that this performance gap is minimal, suggesting that open-weight models are closing the capability distance with closed, restricted frontier models.
Tom's Hardware reported that the implications of these findings are significant for the ongoing debate over AI governance. The outlet highlighted that while Anthropic CEO Dario Amodei has publicly called for pacing the development of the AI frontier, his company recently released Claude Opus 5.5 and Claude Sonnet 5.5 just days after raising alarms about model safety. This timing has drawn criticism from observers who see a contradiction between the company's public advocacy for regulation and its commercial release strategy. Tom's Hardware noted that Anthropic is currently eyeing an Initial Public Offering, a move that may further complicate its stance on open-source safety standards.
Benchmarking the capabilities of GLM-5.3
The technical details provided in Anthropic's report suggest that GLM-5.3 is not merely capable of simple attacks but can execute complex, chained exploits autonomously. Tom's Hardware explained that when tested on a benchmark targeting "full control-flow hijacks," GLM-5.3 achieved a 4% success rate, slightly below Mythos' 6%. More concerning, according to the report, was the ability of GLM-5.3's lighter "Flash" variant to develop chained exploits in known bugs at a tokenized price of just $20.40. This low cost makes such capabilities accessible to a wider range of actors, potentially lowering the barrier to entry for sophisticated cyber operations.
Anthropic further alleged that the safeguards built into GLM-5.3 are easily bypassed. The report details two primary methods for evading the model's guardrails. The first involves providing a deceptive prompt that encourages the AI to role-play an adversarial autonomous agent, which resulted in a 64% success rate for generating harmful content. The second method involves prefilling the model's thinking tokens to ensure the response proceeds in a specific direction, achieving a 92% success rate. A third method, known as abliteration, was also mentioned, though less detail was provided in the initial reports.
These findings align with a broader trend of security researchers uncovering vulnerabilities in open-weight models. The Register noted that since Anthropic announced Project Glasswing in April, an initiative designed to give select partners access to Mythos-class models for bug hunting, the number of Common Vulnerabilities and Exposures (CVEs) attributed to these advanced models has risen. As of Friday, Mythos and Project Glasswing have uncovered 286 CVEs, according to a tracker maintained by VulnCheck security researcher Patrick Garrity. Until Thursday, only one of these bugs had been exploited in real-world attacks, but that changed recently.
Real-world exploitation and the Mythos connection
The urgency of Anthropic's claims is highlighted by recent events involving the exploitation of a critical authentication-bypass bug in Rejetto HTTP File Server (HFS). The Register reported that researcher Zach Hanley at AI pen-testing company Horizon3 used Mythos to uncover a new flaw in this file server, tracked as CVE-2026-61500. This vulnerability allows for full admin access and remote code execution. Hanley published a video demonstrating the steps to exploit HFS and remotely execute code on the server, highlighting the practical utility of such AI-driven vulnerability discovery.
VulnCheck security researcher Patrick Garrity stated on LinkedIn on Thursday that he began detecting exploitation of CVE-2026-61500 that evening. He added that the initial activity originated from an IP address in China, targeting vulnerable hosts in the United States and Japan. By Friday, Garrity reported four hits from two different IP addresses in the US, which he noted appeared to be coming from a proxy. China-linked digital intruders routinely use compromised devices as proxies to route malicious traffic and disguise their true location, a tactic warned about in a 10-country security advisory in April.
Anthropic's report on GLM-5.3 cites the Center for AI Standards and Innovation's own report, published in late September, which claims that GLM-5.3 can fully automate exploits on a similar level to Mythos. This external validation adds weight to Anthropic's internal benchmarks. The company argues that these capabilities make open-weight models dangerous if not properly safeguarded, as they can be abused to generate harmful content and execute cyberattacks. The report acts as a stark reminder of the dual-use nature of advanced AI models and the challenges of governing their release.
For developers and security teams, the takeaway is clear: open-weight models require rigorous testing and monitoring. The Register advised that if you use Rejetto HFS, you should update to version 3.2.1 or later to fix the security flaws. More broadly, the incident highlights the need for strong security practices in an era where AI can accelerate the discovery and exploitation of vulnerabilities. As the capabilities of models like GLM-5.3 and Mythos continue to grow, the line between defensive security tools and offensive weapons becomes increasingly blurred.
Anthropic's position on this issue is complex. While it claims that Mythos is too powerful to release to the general public, it is simultaneously advocating for governance and regulation of the AI field. The company's actions, including the release of new Claude models and its push for an IPO, suggest a business model that relies on the rapid deployment of AI capabilities. This tension between commercial interests and safety concerns is likely to remain a central theme in the AI industry's future. The report on GLM-5.3 is the latest chapter in a growing narrative about the risks and rewards of open-weight AI.
Sources
10- 01Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack showsEN
- 02Anthropic claims popular Chinese AI model has Mythos-class hacking abilitiesEN
- 03OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worseEN
- 04US road rage killer's sentence quashed because AI video of victim was shown in courtEN
- 05Twelve AI clay films for $184: The agents cost more than the video modelEN
- 06Kolibri: A Sovereign Open-Weight ModelEN
- 07New in Llama.cpp: Decision ModelsEN
- 08Shield: A 118M model for detecting prompt injections and jailbreaksEN
- 09Open 10-player CS:GO dataset for multiplayer world modelsEN
- 10We diffed all 66 release pairs of the official MCP servers, 140 silent changesEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.