Feeds.4Sysops China's GLM-5.2 AI Model Matches US Cybersecurity Tools, Raising Security Concerns
Article Content
- •Zhipu AI's GLM-5.2 model competes with Anthropic's Claude Mythos in vulnerability detection.
- •The model's open-weight nature allows both defensive and offensive uses, raising security risks.
- •U.S. export control policies are being questioned due to advancements in Chinese AI capabilities.
Zhipu AI has launched its open-weight model GLM-5.2, which reportedly rivals Anthropic's Claude Mythos in detecting software vulnerabilities. This model's capabilities were confirmed through IDOR benchmark tests by Semgrep, indicating a significant advancement in China's AI hacking skills. The open availability of GLM-5.2 allows both security professionals and potential attackers to utilize it, raising concerns about its use in cyberattacks. The U.S. government is particularly affected, as this development questions the effectiveness of its AI export control policies. Security firms and CERTs in Europe may benefit from using the model in compliance with GDPR, but the risk of misuse by malicious actors remains high. Zhipu AI acknowledged that GLM-5.2 exhibited increased reward hacking during its training, prompting the integration of anti-hacking safeguards. This situation highlights the growing competition between U.S. and Chinese AI technologies in cybersecurity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…