- Zhipu has launched its GLM-5.3 model, claiming it beats Anthropic's Mythos 5 in a key cybersecurity test.
- GLM-5.3 achieved a score of 84.5% on CyberGym, surpassing Mythos 5's 83.8% and GPT-5.6 Sol's 83.6%.
- However, GLM-5.3 scored 54.4% on ExploitBench, trailing behind Mythos 5's 78% and GPT-5.6 Sol's 76.5%.
- Z.ai plans to release GLM-5.3 publicly in about two weeks after completing security assessments, with sensitive functions under a 'trusted access' programme.
- Z.ai has announced an 'Open Source Shield' initiative to audit open-source projects and provide model access for defensive work.
- Zhipu's GLM-5.3 model was tested with security teams in China, identifying 2,436 vulnerabilities across 269 projects, with 1,097 rated medium to high severity.
- The launch of GLM-5.3 is seen as a challenge to the restricted-access model of Mythos, advocating for open-source software and smaller security teams.
- GLM-5.3 differs from other models as it is a general-purpose coding model that acquired cybersecurity capabilities through expanded post-training and reinforcement learning.
Chinese AI startup Z.ai has unveiled its GLM-5.3 model, claiming it achieved an 84.5% success rate on the CyberGym test, surpassing Anthropic's Mythos 5 at 83.8%. This benchmark evaluates a model's ability to identify and validate security flaws in source code.123
Zhipu, the company behind Z.ai, stated that GLM-5.3 was tested against real-world codebases, identifying 2,436 vulnerabilities across 269 projects, with 1,097 rated medium to high severity. However, the model fell short in exploit capabilities, scoring 54.4% on the ExploitBench test, compared to Mythos' 78% and OpenAI's GPT-5.6 Sol at 76.5%.47
In a timed test, GLM-5.3 completed 105 attack-development tasks in two hours and 130 in six hours, while Mythos 5 completed 181 and 247 tasks respectively. Z.ai plans to release GLM-5.3 publicly in two weeks, with enhanced security measures and a "trusted access" program for sensitive functions.5
Z.ai's launch challenges the restricted access model of Mythos, advocating for open-source tools in cybersecurity. The company aims to support smaller security teams and developers by initiating an "Open Source Shield" initiative to audit open-source projects and provide model access for defensive work.
Despite the advancements, critics warn that enforcing safeguards becomes challenging once models are publicly available, raising concerns about potential misuse.
“GLM-5.3 trails on ExploitBench, scoring 54.4% versus Mythos 5's 78%, and completed 105 attack-development tasks in two hours versus Mythos' 181. Z.ai plans a public release in about two weeks, with sensitive functions under a 'trusted access' programme.”






