GLM-5.3 can autonomously build end-to-end cyber exploits, but unlike other frontier models, it was released without meaningful safeguards to limit misuse.
230 comments
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
Interesting play before an IPO...
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).
For all the good things Anthropic makes, it is a very unhinged company.
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
There was this incident that seemingly flew under the radar (52 days ago): https://news.ycombinator.com/item?id=49216185
6 months ago: https://news.ycombinator.com/item?id=47288552
This one also flew under the radar
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
https://www.goodreads.com/quotes/7515521-william-roper-so-no...
How? The big corps are rapaciously eating all IP, demonstrating that the law doesn't apply to them anyway.
When they compete with the Chinese, who won't respect their IP, only then are they competing on an even playing field.
If the only choice you have is Anthropic or OpenAI, where will the money go?
It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
* low/no margin, unlike the API which is very high margin
* gym-membership subsidised - most subscribers don't max them out, mainly us coders are being "subsidised" from users just using it as a research chatbot
Anthropic has been telling everyone that these models are dangerous. OpenAI and Anthropic failed to contain their tests.
Given the history, this testing is extremely reckless. I think it is criminal, it endangers others.
Anthropic has no authority here and they are going too far. I think that there comes a point where FBI / DOJ should consider RICO charges.
are you under the impression that a LLM can grant wishes like a genie?
That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.
In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
> said providers are not "building models for free for the public."
I am part of the public, and they built a model I can run for free.
> They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
They are also doing that, which, good. It can't only be that "competition is good" until you're the one losing to the competition.
That's just the same thing said again but from a butthurt USian perspective. China is freeing the rest of us from US dominance.
if models can find and exploit bugs this fast, anything sitting on a public IP is going to get tested harder and faster.
soon, you'll just have to live under the assumption that an attacker could theoretically get into your infra - so all your precautions will need to have that as a baseline
hence, betting on "undiscoverable resources" as the next big enterprise push!
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
Getting DS4 to run at a reasonable speed was pretty tricky, GLM 5.3 a lot trickier because if you don't want to have a model that is quantized too far down that is a fortune in VRAM and GPUs at today's prices.
If you have a lot of system RAM you could technically run Qwen Flash Next. On a 4080 with 16GB of RAM and 128GB of DDR5 I get ~35-40 t/s. And it is very capable.
For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.
For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.
Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.
Read the full thread on Hacker News →
Related stories
- Hacker News · 1 points · about 22 hours ago
- Lobsters · 18 points · 6 months ago
- Hacker News · 1 points · about 23 hours ago
- Turning GLM-5.3-Flash into a Jev-like decision modelprivatemode.aiHacker News · 113 points · 5 days ago
- The Artificial Analysis Cyber Indexartificialanalysis.aiHacker News · 1 points · 2 days ago
- Ask HN: How are you conforming to EU Cyber Resilience Act (CRA) reporting rules?digital-strategy.ec.europa.euHacker News · 2 points · 5 days ago