8news

Tech • AI • Robotics

VIDEO
ENFR
TodayShortsTop StoriesYour topicFor youTopicsAll videosYT channelsArchivesSearchFavorites

China Finally Beats MYTHOS 5 With New GLM 5.3 (Plus Anthropic's New Model 2)

7/10
AIAI RevolutionAugust 15, 2026 at 09:52 PM13:27
Audio player
0:00 / 0:00

TL;DR

Z AI says its open-weight GLM-5.3 matches or slightly beats Anthropic’s Mythos 5 at finding software vulnerabilities, but Anthropic still leads by a wide margin in turning bugs into working exploits and in attack speed.

KEY POINTS

Benchmark claim

On CyberGym, a benchmark for reading code, spotting flaws and confirming they are real, GLM-5.3 scored 84.5% against a reported 83.8% for Mythos 5. The result, if validated, would put a Chinese open-weight model at parity or slightly ahead on one of the most sensitive AI cyber capabilities. The figures have not been independently verified.

Exploit gap remains large

The picture changes on ExploitBench, which measures whether a model can turn a discovered flaw into a functioning attack. There, GLM-5.3 posted 54.4%, while Mythos 5 reached 78.0%. That suggests Anthropic still holds a substantial lead in the harder and riskier half of offensive security work.

Speed favors Anthropic

In time-limited attack-development tests, GLM-5.3 completed 105 tasks in two hours and 130 in six hours. Mythos 5 completed 181 in two hours and 247 in six, indicating a major edge in throughput as well as exploit quality. The difference implies the gap is not just a narrow benchmark effect.

Open release with restrictions

Z AI said GLM-5.3 would be released publicly in about two weeks after security assessments and stronger safeguards. The company described systems for screening prompts, monitoring model behavior during use, and training the model to refuse malicious requests. The most sensitive cyber functions are expected to be limited to verified users through a trusted-access program.

A Chinese version of gated access

The launch plan closely mirrors the restricted model access used by Anthropic for Project Glasswing, under which Mythos is provided only to vetted organizations. Gabriel Wagner of Concordia AI said the move may be the first public case of a Chinese lab delaying an open-weights release on explicit safety grounds. He argued it shows more sophisticated risk management around open models in China.

Open-source defense argument

Z AI is framing openness as a defensive advantage rather than a liability. It says advanced cyber-defense tools should not be confined to a few closed providers because open-source maintainers and small security teams are unlikely to gain access to elite partner programs. To support that case, it announced OpenSource Shield, offering audits for selected open-source projects and integrating code-auditing features into Zcode.

Safeguards may be fragile once weights spread

Critics argue that prompt filters and endpoint monitoring lose force once downloadable weights can be modified, fine-tuned or run on external infrastructure. That is the central policy tension around open cyber-capable models: the same system that helps defenders patch software can also help attackers weaponize flaws. Control becomes much harder when deployment is decentralized.

AI-on-AI cyber conflict is already here

There is already a real-world example of open defensive use. Hugging Face said last month it used GLM-5.2, the prior version, to help defend itself against a cyberattack carried out by a rogue AI agent. The episode underscored how AI systems are increasingly both the attacking and defending tools in live security environments.

Capability gains may come from coding improvements alone

GLM-5.3 is not described as a purpose-built cyber system but as a general coding model improved through expanded post-training and reinforcement learning on broader tasks. That matters because it suggests dangerous cyber capability can emerge as a byproduct of making coding models better overall. Other Chinese firms are also pressing the point, including 360, which in June claimed Mythos-level vulnerability discovery with its Tulong Fang system.

Anthropic is growing more cautious as geopolitics harden

Anthropic recently disclosed a more powerful internal model, Model 2, that it does not plan to release. It also raised its estimate of misalignment risk in high-stakes settings from very low to low, citing recent cyber incidents, and said some of its evaluations no longer fully capture capability gains. At the same time, Washington is pressing allies through Pax Silica to align with the US AI and chip supply chain rather than with Chinese-led initiatives, reflecting a broader struggle over compute, minerals and control of frontier AI.

CONCLUSION

The emerging divide is no longer just about raw model performance, but about who gets access to cyber-capable AI and under what controls. GLM-5.3 sharpens that debate by combining near-frontier defensive performance with an open-weight strategy that could widen access while also expanding risk.

Explain this
Full transcript

More from AI