Anthropic warns of autonomous cyber attack capabilities in GLM-5.3
October 2, 2026 · 1 min read
Also published in Türkçe, Français, Español, Português (Brasil)
On September 29, Anthropic announced that it has verified the AI model ‘GLM-5.3’ from Zhipu AI (Z.ai) can autonomously construct end-to-end attack code. The model’s weights are publicly available, which Anthropic considers problematic as this allows anyone to download and utilize it.
In an evaluation targeting known vulnerabilities in the V8 engine used by Google Chrome, the model succeeded in creating a series of attack codes in 50 out of 410 attempts. Additionally, during experiments with researchers, multiple unknown vulnerabilities in the browser were discovered, leading to the construction of attacks that could read files within a device.
Since GLM-5.3 is released as an open-weight model, users can modify the safety features themselves. According to Anthropic, the version of GLM-5.3 that underwent weakening of safety measures showed a significantly reduced rejection rate for harmful requests. Within days of its release, a modified version was reported to have been published by a third party.
Anthropic pointed out that the ability to freely access AI with advanced cyber capabilities has entered a new phase. However, it also noted that the same capabilities could be utilized for defense, such as discovering and fixing vulnerabilities, and called for enhanced safety measures and evaluations by third parties.