Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Chinese AI firm Z.ai releases GLM-5.3 coding model, claims discovery of 2,436 vulnerabilities
00

Chinese AI firm Z.ai releases GLM-5.3 coding model, claims discovery of 2,436 vulnerabilities

Aug 14, 2026

Chinese AI firm Z.ai has released its GLM-5.3 coding model, which achieved significant performance gains entirely through post-training reinforcement learning on its existing 743-billion-parameter base. During scaling, the model developed unexpected, advanced cybersecurity capabilities, including multi-step exploit-chain reasoning. It has already identified 2,436 vulnerabilities across 269 projects, including a serious flaw in the Cursor code editor. Due to these dual-use capabilities, Z.ai has delayed its open-weights release by two weeks until August 28, 2026, to conduct rigorous safety evaluations.

GLM-5.3 model release

  • ▪Chinese AI firm Z.ai released its GLM-5.3 coding model on August 13, 2026, initially available only through its GLM Coding Plan and ZCode environment.
  • ▪GLM-5.3 runs on the same 743-billion-parameter mixture-of-experts base model as GLM-5.2, activating roughly 40 billion parameters per token.
  • ▪Z.ai introduced a breaking API change in GLM-5.3 requiring developers to enable thinking and specify a reasoning effort level of low, high, or max.

Post-training scaling methodology

  • ▪Z.ai scaled post-training using automated pipelines where research agents convert real work patterns into runnable tasks and judge agents verify solutions.
  • ▪All performance gains in GLM-5.3 were achieved entirely through scaling post-training reinforcement learning across more environments and diverse tasks without modifying the base model.
  • ▪Z.ai utilized three core post-training components for GLM-5.3: IndexShare for long-context, Scalable Agentic Optimization for reinforcement learning, and the Slime asynchronous framework.

Cybersecurity capability emergence

  • ▪During post-training scaling, GLM-5.3's cybersecurity capabilities developed faster than Z.ai anticipated, progressing from simple vulnerability discovery to multi-step exploit-chain reasoning.
  • ▪Z.ai developer advocate Lou posted on X that GLM-5.3's cyber capabilities identified a potentially serious vulnerability in the Cursor AI coding editor.

Vulnerability discovery results

  • ▪Z.ai's vulnerability findings span system kernels, operating systems, browser engines, and network protocols, with the oldest discovered flaw dating back to 1981.
  • ▪Z.ai models have identified 2,436 vulnerabilities across 269 projects, with 1,097 classified as critical or high severity, since the introduction of GLM-5.2.
  • ▪Z.ai maintains a public Security Disclosure Ledger at cvd.z.ai, where 53 CVEs have been assigned while 2,383 vulnerabilities remain under embargo.

Delayed open-weight release

  • ▪Z.ai committed to releasing the open weights of GLM-5.3 to Hugging Face on August 28, 2026, representing a two-week delay for safety evaluation.
  • ▪The two-week open-weights delay is the first time Z.ai has held back a GLM model release, driven by the model's unexpected offensive cybersecurity capabilities.
  • ▪The US Bureau of Industry and Security added Z.ai's parent entity, Beijing Zhipu Huazhang Technology, to the Entity List in January 2025.

Benchmark performance comparisons

  • ▪On Terminal-Bench 3.0, GLM-5.3 scored 28.3, representing a significant increase from GLM-5.2's 4.6 but trailing OpenAI's GPT-5.6 Sol at 34.6.
  • ▪On the CyberGym vulnerability discovery benchmark, GLM-5.3 scored 84.5%, narrowly leading Anthropic's Mythos 5 at 83.8% and OpenAI's GPT-5.6 Sol at 83.6%.
  • ▪On ExploitBench, GLM-5.3 scored 54.4%, more than doubling GLM-5.2's 24.4% but trailing Anthropic's Mythos 5 which scored 78%.

6 sources

The Decoder
Zhipu AI releases GLM-5.3, claims it's the strongest open-weights coding model
View source article
Venturebeat
GLM-5.3 is here with advanced cyber capabilities — and reportedly already found a 'serious vulnerability' in Cursor
View source article
Cryptopolitan
Better than Anthropic's Mythos 5: China's Z.ai makes bold GLM-5.3 claim - Cryptopolitan
View source article
Techtimes
GLM-5.3: Post-Training Produced Exploit Chains Z.ai Never Planned, Finds 1,097 Critical Bugs
View source article
Decrypt
China's Z.AI Ships GLM-5.3, Calling It the Top Open-Weight Coding Model - Decrypt
View source article

Featured stories

View more in Open source AI ecosystems & communities

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

AMD acquires AI startup World Labs founded by Fei-Fei Li for $8.2 billion

Sep 28, 2026 · 7 sources

Story comments

Loading comments…

Related entities

China

Related Projects

Z.aiCursor

Topics

Open source AI ecosystems & communitiesAI securityAI research & benchmarksAI coding assistantsOpen weights vs closed modelsChina

Featured stories

View more in Open source AI ecosystems & communities

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

AMD acquires AI startup World Labs founded by Fei-Fei Li for $8.2 billion

Sep 28, 2026 · 7 sources