GLM-5.3 surpasses Mythos 5 in cybersecurity test

Z.ai announced that its GLM-5.3 model outperformed Anthropic's Mythos 5 in a cybersecurity test, scoring 84.5% on CyberGym versus 83.8%. However, the Chinese model lagged behind in vulnerability exploitation, with 54.4% on ExploitBench against the rival's 78%. The results have not yet been independently verified.

GLM-5.3 surpasses Mythos 5 in cybersecurity test

Chinese startup Z.ai announced on Friday (14) that its open-source model GLM-5.3 narrowly surpassed Anthropic's Mythos 5 in a cybersecurity test. On CyberGym, which assesses the ability to review code, identify flaws and confirm they are genuine, GLM-5.3 scored 84.5%, against 83.8% for its rival. OpenAI's GPT-5.6 Sol came in third with 83.6%. The figures were released by Z.ai itself and have not yet undergone independent verification. The company said it will launch the model publicly in about two weeks, after completing security assessments.

The Chinese model's advantage, however, disappears when the task requires turning vulnerabilities into functional attacks. On ExploitBench, which measures the ability to exploit flaws, GLM-5.3 recorded 54.4%, while Mythos 5 reached 78% and GPT-5.6 Sol, 76.5%. In a timed test, GLM-5.3 completed 105 attack development tasks in two hours and 130 in six hours. Mythos 5, in the same windows, completed 181 and 247 tasks, respectively. These figures indicate that, although the Chinese model is efficient at identification, there is still a significant gap in the practical execution of exploits.

Modelo de IA analisa código para identificar vulnerabilidades.
Modelo de IA analisa código para identificar vulnerabilidades.

GLM-5.3 is a general-purpose coding model that, according to Z.ai, acquired cybersecurity capabilities through expanded post-training and reinforcement learning. The company said it added several layers of protection, including systems to filter risky requests, monitor the model's operation and train it to reject malicious tasks. The most sensitive functions will only be available to verified users through a "trusted access" program. Z.ai also highlighted that GLM-5.2, the previous version, was used by Hugging Face to defend against a cyberattack perpetrated by an OpenAI AI agent. The move reinforces the Chinese company's position as an open-source alternative to closed American models.

The news arrives amid fierce competition between Chinese and American companies in the field of artificial intelligence. In June, cybersecurity firm 360 claimed that its Tulongfeng system had achieved capabilities equivalent to those of Mythos, although the claims were not independently verified. Z.ai, for its part, argues that advanced cyber defense tools should be accessible to open-source software developers and smaller security teams, rather than being controlled by a limited number of vendors. GLM-5.3's performance, albeit partial, signals that the gap between open and proprietary systems is narrowing. Experts, however, recommend caution until the results are confirmed by external evaluations.

Komentarze 0

Loading comments...

Loading comments...