Z.ai just pulled GLM-5.3 into one of the most important AI fights happening right now: who gets access to frontier-level cybersecurity capability, and how open should that access actually be?
The company says its upcoming GLM-5.3 model can nearly match, and in one benchmark slightly beat, Anthropic’s restricted Mythos 5 at finding real software vulnerabilities. At the same time, Z.ai is launching an Open Source Shield initiative aimed at putting more advanced defensive tools into the hands of open-source developers and smaller security teams.
That combination makes this more interesting than a normal model update. Z.ai isn’t just talking benchmark points. It’s making a pretty direct argument that serious cyber-defense capability shouldn’t live entirely behind closed access programs.
GLM-5.3 is going straight at Mythos 5
The headline number comes from CyberGym, a benchmark built around reviewing code, identifying vulnerabilities, and confirming whether those vulnerabilities are real.
Z.ai says GLM-5.3 scored 84.5% on CyberGym. It reports Anthropic’s Mythos 5 at 83.8%.
That’s close enough that the practical takeaway isn’t really “GLM wins.” It’s that an upcoming open model is now being positioned in the same neighborhood as one of the most tightly controlled cybersecurity models in the world.
There’s an important caveat here: these are Z.ai’s reported results and they haven’t been independently verified yet. Cybersecurity benchmarks are exactly the kind of numbers where I want to see outside replication before turning a vendor chart into gospel.
Mythos 5 still has a major advantage on exploitation
The fuller benchmark picture is a lot more useful than the headline.
On ExploitBench, which measures whether a model can turn discovered vulnerabilities into working exploits, Z.ai says GLM-5.3 scored 54.4%. Mythos 5 scored 78.0%.
That’s not a rounding error. Mythos still has a substantial lead when the task moves from finding a vulnerability to actually weaponizing it.
The timed attack-development numbers tell a similar story. Z.ai says GLM-5.3 completed 105 tasks in two hours and 130 in six hours. Mythos 5 completed 181 and 247, respectively.
So I wouldn’t describe GLM-5.3 as “beating Mythos 5 at cybersecurity.” That’s too broad. What Z.ai appears to have is a model that can compete extremely well at vulnerability discovery while still trailing significantly on exploit development.
The open-source angle is the real story
This is where GLM-5.3 gets especially interesting.
Anthropic has kept Mythos behind a vetted-access model because advanced cyber capability is inherently dual-use. The same system that can help a security team find a critical flaw can also help an attacker find it first.
Z.ai is taking a different path. The company says it plans to release GLM-5.3 publicly in roughly two weeks after finishing security assessments and strengthening safeguards. The most sensitive cybersecurity functions will still sit behind a verified-user “trusted access” program.
That means this isn’t unrestricted access to every capability for everybody. But it is a much more open posture than keeping the whole model locked behind institutional vetting.
Z.ai says GLM-5.3 will use multiple layers of protection, including risky-request screening, monitoring of the model’s work, and training designed to reject malicious tasks while preserving legitimate use cases such as bug fixing, education, and authorized security testing.
What is Open Source Shield?
Alongside the model announcement, Z.ai is starting an initiative called Open Source Shield.
The plan is to audit selected open-source projects, provide model access for defensive security work, and add code-auditing capabilities to ZCode, Z.ai’s agentic coding environment.
I like this framing more than another generic “AI for security” launch. Open-source maintainers are often responsible for software used by millions of people while operating with nowhere near the security resources of a giant enterprise. Giving those developers better automated auditing could be genuinely useful.
Of course, the hard part is keeping a capable open model useful to defenders without making the offensive side trivially easy to unlock. Once weights are downloadable, safeguards become much harder to enforce than they are on a hosted API.
GLM-5.3 builds on the same base as GLM-5.2
Z.ai says GLM-5.3 isn’t a purpose-built cybersecurity model from scratch. It uses the same underlying base as GLM-5.2, with additional post-training and reinforcement learning across longer and more varied task environments.
That matters because GLM-5.2 was already a serious open coding model, with a 1M-token context window and MIT-licensed weights. I also covered earlier evidence that GLM-5.2 was punching above its weight on security-focused coding benchmarks.
GLM-5.3 looks like Z.ai taking that foundation and deliberately pushing it deeper into security work.
Why this matters
The bigger story here is access.
I’ve covered the strange new reality around models like Mythos 5, where labs are building systems with extremely valuable defensive capabilities and then restricting them because the offensive potential is just as real. Anthropic’s Mythos rollout has already shown how narrow that access can become.
GLM-5.3 puts pressure on that entire model.
If Z.ai’s numbers hold up, smaller security teams may soon have access to vulnerability-discovery capability that’s at least competitive with a system most organizations can’t use at all. That could be great for defenders. It could also make the dual-use problem much harder for everyone.
Either way, the gap between “open model” and “frontier cyber model” is getting very small, very fast.




