GLM-5.3 ships as open weights with SOTA vulnerability-discovery and exploit skills
Z.ai has released GLM-5.3 as an open-weights model on Hugging Face. It reuses the GLM-5.2 base model unchanged, so the entire jump in capability comes from post-training. On coding the company claims a 50% gain over GLM-5.2 on its internal Code Bench and open-source top scores on public agentic suites like Terminal-Bench 3.0 and Agent’s Last Exam, positioning it as the strongest open-weights coding model currently available.
The more notable angle for security teams is what Z.ai calls an emergent cyber capability that grew faster than expected as post-training scaled. GLM-5.3 leads CyberGym on vulnerability discovery, and its biggest gains land further up the exploitation chain, where it more than doubles GLM-5.2 on exploit-focused benchmarks. In practice that means a freely downloadable model tuned to find bugs and build working exploits — a clear dual-use concern, even though the vendor notes it applied domain whitelisting and rule- plus LLM-based judging during evaluation to keep the agent from cheating or running unauthorized commands.
The model is broadly deployable, with documented support for Transformers, vLLM, SGLang, KTransformers, Unsloth, Docker, and Ascend NPU stacks, plus a reasoning_effort control (low/high/max) to trade off thinking budget. The combination of open weights, strong autonomous-agent performance, and benchmark-leading offensive security ability makes this release worth watching for both red teams and defenders.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.