Scmp Kimi K3 Cyber Capabilities Assessed: Significant Gap with US Models
Article Content
- •Kimi K3 scored 32.2% on the ExploitBench benchmark, far below US rivals.
- •The model failed to achieve arbitrary code execution in all tested tasks.
- •The assessment indicates a significant gap in cyber capabilities between US and Chinese AI models.
A joint evaluation by the UK AISI and US CAISI assessed China's Kimi K3 AI model, revealing it has a cyber capability score of 32.2%, significantly lower than top US models averaging 76.2%. Kimi K3, released on July 16, 2026, failed to achieve arbitrary code execution across all 41 tasks in the ExploitBench benchmark, while leading US models succeeded in 20 tasks. The evaluation raises concerns about the effectiveness of Kimi K3 in launching cyberattacks, despite outperforming a domestic competitor, Zhipu AI's GLM-5.2, which scored 24.4%. The findings challenge perceptions of the rapid advancement of Chinese AI in cybersecurity. The report highlights the need for further assessments as Kimi K3 is set for open-weight release on July 27, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…