GLM (Z.ai)

11 items · open weights · Capability 7 · Defense 2 · Attacks 2 · all entities

Anthropic names seven China-based AI companies it says ran industrial-scale distillation against Claude

The Hacker News, reading Anthropic's September 2026 misuse report, says the company attributes illicit distillation campaigns to seven China-based labs and gives each a tracking identifier: Alibaba (GTG-16005), Moonshot AI (GTG-16002), DeepSeek (GTG-16001), Zhipu/Z.ai (GTG-16006), Xiaomi (GTG-16008), SenseTime (GTG-16012) and MiniMax (GTG-16003). It reports 151 million exchanges attributed to Alibaba from more than 3,500 fraudulent accounts between May and July 2026, 23 million to Moonshot from 5,380 accounts over the same window with almost 300,000 customer requests relayed in ten days, and more than 12.1 million to DeepSeek over 14 days in July. Five of the seven — Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax — also appear in the September 8 NSA/CISA/FBI advisory; Xiaomi and SenseTime do not, and StepFun, which the advisory names, is not among Anthropic's seven.

Reported by pressAnthropic (via The Hacker News) ↗ ·

Joe Security analyses ToxNetV2, a Linux botnet that queries a jailbroken hosted LLM to propose attack commands

Joe Security reported that the ToxNetV2 Linux botnet, which targets AArch64 systems over a peer-to-peer command-and-control channel, feeds host telemetry to Z.ai's GLM-5.2 model reached through NVIDIA's NIM service — using an explicit “ENI/VEIL” jailbreak to reduce refusals — and queues the model's suggested shell and SSH actions for a human operator to approve and run with an “aiexec” command. The analysis noted the malware carries 17 network-attack launchers and that higher-impact AI suggestions still require operator approval rather than executing autonomously.

Reported by researchersJoe Security (via Cyber Security News) ↗ ·

Kimi K3 is the first open-weight model to record a verified solve on Irregular's scenario suite

Irregular reports that Kimi K3, a 2.8-trillion-parameter mixture-of-experts model with 104 billion active parameters, is the first open-weight model it has evaluated to record a verified solve on CyScenarioBench, where GLM-5.2 solved none. On the harder FrontierCyber suite Kimi K3 produced no verified solves. Irregular states the strongest closed frontier models still hold a clear advantage in converting technical capability into sustained operational success, and publishes no numeric scores on the page.

Reported by researchersIrregular ↗ ·

Z.ai launches GLM-5.3 with self-reported cyber gains, then holds its open weights back for a safety review

Z.ai released GLM-5.3, the successor to GLM-5.2, reporting its own result of 84.5% on the CyberGym cyber-offense benchmark — ahead of the scores it cited for Claude Mythos 5 and GPT-5.6 Sol — and saying the model found 2,436 vulnerabilities across 269 open-source projects, 1,097 of them rated critical or high, including bugs in Linux, WebKit and FreeBSD. Z.ai also said it would hold the open-weights release back by roughly two weeks for a cyber-safety review, citing an unintended emergent ability to reason across multiple stages of exploitation and form coherent full-chain exploitation plans; the figures are vendor-reported and none has been independently reproduced.

Reported by pressAI Weekly (reporting Z.ai) ↗ ·

Contamination-free reverse-engineering benchmark finds the strongest model fully solves under a third of cases

SRE-Bench, a preprint benchmark of 19 private programs averaging 16,915.8 lines of code, 262 binary instances and 1,572 deterministically graded tasks with 44 anti-analysis primitives, reports that “the strongest model, GPT-5.6-sol, scores 61.4% per instance, and fully solves only 31.5% of the instances.” The other models tested trail well behind — Claude Opus 5 at 31.8%, GPT-5.5 at 17.1%, Grok 4.5 at 7.6% and GLM-5.2 at 3.4% — and the authors conclude strong source-code security capability does not yet transfer to binary analysis. Not peer reviewed.

Reported by researchersarXiv preprint 2608.11469 ↗ ·

Two open-weight models match a frontier model on a re-run of previously unsolved AI red-team tasks

Dreadnode re-ran 13 AIRTBench tasks that had previously been unsolved or solved by only one model. GLM-5.2, Kimi-K3 and Claude Sonnet 5 each solved 10 of 13 at AIRT@1, Qwen3.7-Plus and Nemotron-3-Ultra 6 of 13, and Trinity-Large-Thinking 1 of 13. The authors call it a system-level follow-on rather than a controlled model-only rerun and say AIRT@1 should be read as a snapshot, not a pass@k reliability estimate.

Reported by researchersDreadnode ↗ ·

UK AISI and US CAISI jointly assess Kimi K3 — safeguards did not stop it attempting offensive cyber

A joint preliminary assessment puts Moonshot's open-weight Kimi K3 at 32% on ExploitBench against GLM-5.2's 24%, still short of US frontier models: it achieved arbitrary code execution on 0 of 41 samples versus 20 of 41, and reached step 17 of the 32-step "The Last Ones" attack path versus 28.5. The institutes state plainly that Kimi K3's safeguards did not prevent it from attempting exploit development or offensive cyber operations during the evaluations.

On the recordUK AI Security Institute / CAISI ↗ ·

UK AISI puts leading open-weight models four to seven months behind the closed cyber frontier

AISI reports that GLM-5.2 and DeepSeek V4-Pro perform similarly to closed frontier models released four to seven months before them, narrowing from the six to ten months it measured through most of 2025. It puts a 100-million-token cyber range run at about $85 for Opus 4.5 and 4.6, about $46 for GLM-5.2 and $1.19 for DeepSeek V4-Pro.

Reported by researchersUK AI Security Institute ↗ ·

Hugging Face ran its breach forensics with an open-weight model after commercial ones refused

In its incident disclosure, Hugging Face says it ran LLM-driven analysis agents over the attacker's full action log of more than 17,000 recorded events to reconstruct the intrusion and scope the blast radius. It names GLM-5.2, an open-weight model it ran on its own infrastructure, as what it used for the forensic analysis.

Confirmed by orgHugging Face ↗ ·

XBOW publishes cross-model offensive-security comparison placing GLM-5.2 and Muse Spark 1.1 near frontier models at lower cost

XBOW ran black-box testing against vulnerable open-source applications across Muse Spark 1.1, GLM-5.2, GPT-5.5, Mythos, Opus 4.6, GPT-5, Gemini models and Grok 4.5. It reported Mythos as strongest, GLM-5.2 falling between GPT-5 and Opus 4.6, and Muse Spark 1.1 landing just below Opus 4.6, concluding that 'good-enough offensive capability is getting much cheaper, and that changes the threat model.'

Self-reported, untestedXBOW ↗ ·

The best model judge gating an offensive agent's tool calls still falls short of human graders

ScopeJudge benchmarks eight models as pre-execution judges deciding whether an offensive-security agent's next tool call is in scope, over 4,897 tool calls of which 7.7% are scope violations, against a human-expert reference of F1 0.78 and inter-grader agreement of Fleiss kappa 0.64. GLM-5.2 reaches F1 0.66, the highest of any judge tested, against 0.60 for the best proprietary judge at roughly one-third the per-call cost. The authors conclude static policy is structurally insufficient for scope enforcement.

Reported by researchersDreadnode / arXiv:2607.07774 ↗ ·