www.nist.gov GLM-5.3 Model Enhances Cyber Exploitation Risks
Article Content
- •Z.ai's GLM-5.3 model has been released with minimal safeguards, increasing exploitation risks.
- •NIST's CAISI assessment ranks GLM-5.3 as the most capable open-weight model to date.
- •Attackers can bypass GLM-5.3's protections with alarming ease, raising concerns for defenders.
The release of Z.ai's GLM-5.3 AI model on August 14, 2026, has raised significant cybersecurity concerns due to its advanced capabilities for developing cyber exploits. NIST's CAISI assessment indicates that GLM-5.3 is the most cyber-capable open-weight model available, but it lacks effective safeguards, allowing attackers to bypass them easily. Simulated tests showed that attackers could circumvent GLM-5.3's protections between 64% and 100% of the time. This model can autonomously create exploits targeting known vulnerabilities, including those in widely used software like Google Chrome's V8 engine. The model's public availability increases the risk of malicious use, particularly as it lags U.S. frontier models by four months in cyber capabilities. The situation is compounded by the active exploitation of CVE-2026-11645, which was added to CISA's KEV list shortly after its publication. Overall, the combination of GLM-5.3's capabilities and the ongoing exploitation of vulnerabilities poses a serious threat to cybersecurity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-11645 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…
Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine, rated 8.8 on the CVSS scale. The flaw, identified as a type confusion issue, allows remote attackers to execute arbitrary code within Chrome's sandbox by…