Zhipu's GLM-5.3 Edges Out US Models on Cyber Benchmark
The new open-weights model GLM-5.3 scores 84.5% on CyberGym — narrowly ahead of Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol at finding vulnerabilities.

Illustration · AI-generated (AI IN LIFE)
At a glance
- 84.5% on CyberGym — ahead of Mythos 5 (83.8%) and GPT-5.6 Sol (83.6%)
- Only 54.4% on ExploitBench — well behind the US models
- Found 2,436 vulnerabilities across 269 real projects
- 1,097 findings confirmed as medium-to-high severity
- Open-weights release planned, with tiered access controls
Beijing-based AI firm Zhipu (known internationally as Z.ai) unveiled its new flagship model GLM-5.3 on August 14 — and its cyber capabilities are drawing the most attention. On CyberGym, a benchmark measuring vulnerability discovery, the model achieves an 84.5 percent success rate according to Zhipu, narrowly ahead of Anthropic's Mythos 5 (83.8 percent) and OpenAI's GPT-5.6 Sol (83.6 percent).
The gap between defense and offense is striking: on ExploitBench, which measures the ability to exploit vulnerabilities, GLM-5.3 scores 54.4 percent — well behind Mythos 5 (78 percent) and GPT-5.6 Sol (76.5 percent). Zhipu accordingly positions the model as a tool for cyber defense.
In real-world testing with Chinese security teams, GLM-5.3 analyzed production codebases and, according to the company, identified 2,436 vulnerabilities across 269 projects; 1,097 of them were rated medium to high severity after expert review. Reports suggest some of these capabilities emerged during post-training without being explicitly planned.
GLM-5.3 is set to be released as an open-weights model, reportedly with tiered access controls for higher-risk capabilities. Technically, Zhipu relied on improved post-training rather than retraining the base model — with gains in complex coding and long-horizon tasks as well.
The launch comes as China invests heavily in AI-powered cyber defense. For enterprises elsewhere, the development cuts both ways: powerful, freely available security tooling on one hand — and a further escalation of the AI security arms race on the other.
FAQ
What is GLM-5.3?
The new flagship model from Beijing-based Zhipu (Z.ai), notably strong at discovering security vulnerabilities and slated for an open-weights release.
Is GLM-5.3 better than Western models?
Only at finding vulnerabilities (CyberGym), where it leads narrowly. At exploiting them (ExploitBench), it trails Mythos 5 and GPT-5.6 Sol by a wide margin.
Why does this matter?
A freely available model with strong cyber-defense skills lowers the barrier for security teams worldwide — while intensifying the US-China AI competition in security.


