· KrASIA
Z.ai Says Open-Source GLM-5.3 Narrowly Edges Anthropic's Mythos 5 at Finding Software Flaws
Photo: Markus Spiske on Unsplash
Chinese AI company Z.ai published benchmark results claiming its new open-source GLM-5.3 model slightly outperforms Anthropic's restricted Mythos 5 at identifying software vulnerabilities. The company said it will delay the public release by about two weeks for additional safety work and will gate its most sensitive cybersecurity functions behind a verified-user program.
Chinese artificial intelligence company Z.ai has released benchmark figures for GLM-5.3, a new flagship model it says can match or slightly exceed leading US systems at identifying software vulnerabilities while closing the gap with Anthropic on long-running coding tasks. The model uses the same base as its predecessor GLM-5.2 but reports stronger results across coding and cybersecurity evaluations.
On CyberGym, a benchmark that tests whether a model can inspect source code, locate vulnerabilities and verify them, Z.ai said GLM-5.3 scored 84.5%, marginally ahead of Anthropic's Mythos 5 at 83.8% and OpenAI's GPT-5.6 Sol at 83.6%. The numbers were published by Z.ai itself and have not been independently verified.
The picture changes when the task moves from finding a flaw to weaponizing one. Z.ai reported that GLM-5.3 scored 54.4% on ExploitBench against 78.0% for Mythos 5. In timed testing, GLM-5.3 completed 105 attack-development tasks in two hours and 130 in six hours, well short of Mythos 5. Z.ai also said the model surfaced 1,097 critical vulnerabilities across major open-source codebases including Linux, WebKit and FreeBSD during testing, and that exploit-chain reasoning emerged from post-training rather than deliberate design.
Citing those capabilities, Z.ai said it would delay the public release by roughly two weeks to carry out further security checks and strengthen safeguards, with the most sensitive cybersecurity functions initially limited to selected partners and verified users under a trusted access program. Anthropic has taken a more restrictive route with Mythos, a version of its Claude Fable 5 model with cybersecurity safeguards removed that is made available only to vetted organizations.
Markets did not react as they had to earlier releases. Z.ai's Hong Kong-listed shares closed down 3.6% on August 14, the day GLM-5.3 was announced, in contrast with the enthusiasm that greeted GLM-5.2 earlier in the summer, when the stock had risen more than 2,000% from its January listing by late June.
Sources & credits
Original source: KrASIA