Choose Rich Live
Tech

Anthropic warns open GLM-5.3 model approaches Claude Mythos Preview in exploit generation

Anthropic reported that the openly downloadable GLM-5.3 model approaches Claude Mythos Preview in cyber exploit capabilities while lacking robust safeguards against misuse.

Charts from Anthropic comparing GLM-5.3 and Claude Mythos Preview on ExploitBench success rates and measuring GLM-5.3 engagement with malicious attack requests.
Image: @kimmonismus

Anthropic warned that Zai's openly downloadable GLM-5.3 model approaches the cyber exploit capabilities of Anthropic's Claude Mythos Preview, but was released without robust safeguards. According to Anthropic, GLM-5.3 can autonomously build end-to-end cyber exploits, and its built-in protections are easy to bypass.[1][3]

In benchmark testing on ExploitBench, GLM-5.3 built working browser exploits in 50 out of 410 attempts, rivaling the 56 successful attempts recorded by Claude Mythos Preview. In a separate controlled experiment, researchers utilized GLM-5.3 to uncover previously unknown browser vulnerabilities and combine them into an exploit webpage capable of reading files from a test machine.[2][3]

Anthropic also evaluated the model's resistance to malicious prompts, reporting that GLM-5.3 engaged with malicious requests 64% to 100% of the time under various safeguard bypass conditions.[3]

Key facts

  • Anthropic reported that Zai's openly downloadable GLM-5.3 model approaches the exploit capabilities of its Claude Mythos Preview model.
  • Anthropic stated that GLM-5.3 can autonomously build end-to-end cyber exploits but lacks robust safeguards against misuse.
  • On the ExploitBench evaluation, GLM-5.3 generated functional browser exploits in 50 of 410 attempts, compared to 56 for Claude Mythos Preview.
  • In a controlled experiment, researchers used GLM-5.3 to identify previously unknown browser vulnerabilities and combine them into a webpage that read files from a test machine.
  • Anthropic found that GLM-5.3 engaged with malicious requests 64% to 100% of the time across different safeguard bypass conditions.

Sources · 3 sources

  1. TE

    Techmeme@TechmemePost on X ·

    Anthropic says GLM-5.3 can autonomously build end-to-end cyber exploits, like Claude Mythos Preview, but was released without robust safeguards against misuse (Anthropic) (Visit Techmeme dot com for the link and full context!)

    Open source
  2. 阳明

    阳明AI@x_autonomyPost on X ·

    【AI热点】18:00-20:00 更多详细信息→https://t.co/Fl08MxyO5z 1. Anthropic 称智谱开源模型 GLM-5.3 的漏洞利用能力接近 Claude Mythos Preview [影响大·可执行高] Anthropic 发布评估称智谱开源模型 GLM-5.3 的漏洞利用能力接近 Claude Mythos Preview,在 ExploitBench 的 410 次尝试中 50 次构建出可用漏洞利用,Mythos Preview 为 5 2. Kimi K3 与 GLM 5.3 经 Baseten 接入 Codex 企业通道,中国开源模型首次进入 OpenAI 企业采购体系 [影响大·可执行高] Baseten 宣布与 OpenAI 合作,成为 OpenAI B2B 市场首批开源模型推理服务提供商之一,企业用户可通过 Codex 或 Responses API 使用 Kimi K3 和 GLM 5.3 等开源模型,中国开源模型首次进 3. 麦当劳用机器学习为各门店推荐菜单价格 [影响中·可执行低] McDonald’s 正使用机器学习系统分析数百万笔日常交易数据,为美国及部分国际市场的单个餐厅生成菜单价格推荐,考虑因素包括本地竞争和区域价格敏感度。系统为餐厅级推荐而非基于个人数据的个性化定价,加盟商保留最终定价权,但部分加盟商称感受到 4. Google 向约 100 家出版商支付 AI 答案内容费用,金额差异悬殊且算法不透明 [影响大·可执行低] The Information 报道,Google 试点计划向约 100 家数字出版商支付 AI Overviews、AI Mode 和 Gemini 使用内容的费用,金额差异巨大:小站几个月不足 1000 美元,有出版商几个月拿到 5 万 5. vLLM 分离式推理(Disaggregated Serving)实用指南 [影响中·可执行高] vLLM 官方博客发布分离式推理实用指南,讲解 vLLM v0.30.0 及以上版本中 prefill/decode 分离、无 GPU render 前端及两者组合的原理与运行方法。 6. 小红书推荐系统 Agentic 发布实践:跨昼夜长程任务 Harness 详解 [影响中·可执行中] 小红书技术团队详解推荐系统 Agentic 发布实践:一次发布横跨十几个部署组、数千个 Pod,平均持续 10 多个小时,团队将发布知识沉淀为近 20 万字 SKILL,并构建长程任务 Harness,通过任务持久化状态、流程模板、引擎推进 7. 快手高管调整:程一笑兼任社区科学线负责人,于越转任可灵 AI CEO [影响中·可执行低] 快手发布公告宣布高管分工调整,创始人兼首席执行官程一笑兼任社区科学线负责人,原负责人于越转任可灵 AI 公司董事兼首席执行官。程一笑在全员信中表示可灵始终是快手 AI 战略的核心布局。 8. Meshy 7 实现包装文字精准生成 [影响中·可执行高] AI 生成的包装上的文字:模糊、残缺,总要修一轮。这次不一样。😎 我们搭了一整架玩具。看看盒子上的字。 Meshy 7 直接从你的输入图像带来准确的文字、风格和颜色。一次生成,就能得到你想要的纹理。🎨 提示:想用同一种风格做一整套?用 9. 古尔曼:苹果 10 月 13 日进军智能家居,首发 J490 控制中枢及 2027 款 Apple TV、HomePod mini [影响大·可执行中] 苹果计划于 10 月 13 日推出代号 J490 的首款智能家居控制中枢,以及 2027 款 HomePod mini 和新款 Apple TV。J490 采用约 6 英寸方形显示屏,有壁挂(J491)和台面两种版本,靠声音或面部识别区分家 10. 可灵 Kling 4.0 满血版短片展示 [影响中·可执行中] 满血版 KLING 4.0 实战呈现 🎬 #Kling4 #KlingAI #KlingModeOn 11. 荣耀 MagicOS 11 十月升级公布:一碰传支持与 OPPO、vivo、小米跨品牌分享 [影响中·可执行高] 荣耀公布 MagicOS 11 十月体验升级内容,一碰传将支持与 OPPO、vivo、小米手机跨品牌分享,无需安装 App,预计 10 月中旬支持 MagicOS 11 产品,具体上线时间依赖对方手机升级支持。 12. Scaffolding Minds:为多模态推理优化潜在视觉目标表示 [影响小·可执行中] Scaffolding Minds 针对潜在推理两阶段框架的两个缺陷提出改进:用专门学习的 scaffolding encoder 在潜在空间提供优化目标,并同时学习 RL 采样器的均值和方差以支持探索。该方法在 FrozenLake 空间 13. 磐镭 YO2 迷你主机上架:锐龙 AI Max+ PRO 495、192GB+2TB 售 49999 元 [影响小·可执行高] 磐镭 YO2 迷你工作站开启预约,搭载 AMD 锐龙 AI Max+ PRO 495 处理器,192GB 内存 + 2TB SSD 售价 49999 元。 14. Qwen3.8-27B 上线 Nebius [影响中·可执行高] Qwen3.8-27B 现已通过 @nebiustf 开放使用。无论你是在构建智能体还是做深度研究,这个 27B 稠密模型都已为你的多步骤工作流准备就绪!🥳 15. DSH 上下文管理插件 dsh-context 推荐 [影响小·可执行中] 今天推荐一个功能很丰富的 DSH 上下文管理插件 dsh-context: https://t.co/pWLhpI4Zts 16. 启境 GX7 全国交付保证权益上线:10 月 7 日前下订 4 周交付,超期补偿 1000 积分/日 [影响小·可执行中] 启境汽车 9 月 30 日上线启境 GX7 全国交付保证权益:10 月 7 日前下订可 4 周交付,超期按 1000 积分/日补偿(10 积分在华为乾崑 App 商城可抵扣 1 元),产线节假日不停工冲刺产能。 17. 领克 10 全系升级吉利智充:分兆瓦智充版与智充版,最高 900V、12C [影响中·可执行低] 领克 10 全系升级为“兆瓦智充版”与“智充版”两个充电版本,前者支持 900V 和 12C 最高充电倍率,官方称可实现“4 分钟畅行、8 分钟满行”,后者为 800V 和 6C。该车 5 月上市,限时价 16.99 万元起,10 月 1 18. 百度千帆 Token Plan 企业版开启「国庆 Token 畅享」限时活动 [影响中·可执行高] 百度千帆开启「国庆 Token 畅享」活动,即日起至 10 月 7 日 23:59:59,Token Plan 企业版对 DeepSeek-v4.1-flash、DeepSeek-v4-pro-0813、GLM 5.3 三款模型统一按 0. 19. 小米米家三筒洗衣机健康洗 Pro 14kg 系列开售:洗烘款国补价 4999 元,滚筒款 3999 元 [影响小·可执行低] 小米米家三筒洗衣机健康洗 Pro 14kg 系列于 9 月 30 日开售,洗烘款首发价 5999 元、国补后 4998.85 元,滚筒款 4999 元、国补后 3999.25 元。 20. ElevenLabs 正式进军比利时 [影响中·可执行低] 你好,比利时,bonjour Belgique 🇧🇪 我们正在招聘:https://t.co/V0MiLra3c5 21. 百度伐谋杯 AI+航天大赛正式开赛,基于「伐谋」自我演化超级智能体 [影响小·可执行中] 百度智能云太空智能业务部与北航云衔浙航实践队共同发起「百度伐谋杯」AI+航天大赛,以百度智能云「伐谋」自我演化超级智能体为技术底座,衔接商业航天企业真实场景与脱敏数据。每个课题设一等奖 5000 元、二等奖 3000 元、三等奖 2000

    Open source
  3. CH

    Chubby♨️@kimmonismusPost on X ·

    Anthropic doing advertisment for GLM-5.3 was not on my bingo card: Anthropic says Zai's openly downloadable GLM-5.3 approaches Claude Mythos Preview’s exploit capabilities, with safeguards that are easy to bypass. On ExploitBench, GLM-5.3 built working browser exploits in 50 of 410 attempts. Mythos Preview managed 56. In a separate controlled experiment, researchers used GLM-5.3 to discover previously unknown browser vulnerabilities and combine them into a webpage that could read files from the test machine. Anthropic also reports 64–100% engagement with malicious requests under different safeguard bypass conditions. So yeah, interesting times ahead.

    Open source