2026-09-30-Wed · Anthropic · IPO · Zhipu

From Issue 58 (2026-09-30) · 17 stories in this issue

07 RESEARCH

❯ Anthropic says Zhipu’s open GLM-5.3 can autonomously build full cyberattacks but lacks robust safeguards

An open model nears MythosAnthropic published an assessment saying Zhipu’s (Z.ai) openly downloadable GLM-5.3 can, like Claude Mythos Preview, autonomously build end-to-end cyber exploits, from finding a vulnerability to writing working attack code, yet it was released without robust safeguards against misuse, and existing protections are easy to bypass. In the tests, GLM-5.3 achieved full control-flow hijacks in 4% of trials, versus 6% for Mythos Preview.

Mythos is still locked awayA control-flow hijack lets an attacker make a target program run code of their choosing, a key step in breaking into a system. In April, Anthropic limited Mythos Preview to a small group of tech and security companies over concerns about its vulnerability-hunting and exploit skills, refusing a public release. Now a model anyone can download and run offline is approaching that threshold, and open weights, once released, cannot be recalled or restricted after the fact.

Less time for defendersAutomated attack skills once limited to a few top models may soon reach ordinary attackers, further squeezing the window enterprise security teams have to patch holes. The report also has a vantage point: Anthropic is a closed-model company heading into an IPO, and the findings support its argument that stronger capabilities need tighter controls. Still, concrete figures like 4% give regulators and the security industry something tangible to debate.

▪ SIGNALClosed labs can lock up their most dangerous models, but not stop others from building something similar months later; the pace of open-source catch-up now sets how much time cyber defenders get.