Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
show comments
gr_norm
Astounding endorsement of open models by Anthropic. They're right on the money. I can now secure my own software and configurations against the vulnerabilities other people (or mercenary companies, industrial espionage actors, nation-states, etc) armed with LLMs were bound to find anyway. A win on all counts!
show comments
CharlieDigital
Anthropic has to use this wedge (and future ones) to move regulatory action against the Chinese models or their IPO is going to be really problematic.
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
show comments
jacquesm
This is so transparent. Their next move: 'during our testing GLM-5.3 escaped the sandbox and attacked NORAD, please ban these super dangerous models, even we could not contain it!'.
I wonder who the real audience of these messages is.
ddxv
Anthropic is so self centered it's hard for me to comprehend.
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
show comments
bitexploder
This just makes me want a home lab capable of running GLM 5.3 at a 4bit quant.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
show comments
godbox
I have never seen a multi-billion $ company that has such... bizarre? conduct. If you have an AI that genuinely can be a meaningful threat actor, disclose when you will be releasing it a week in advance and release it to the public, meaning everybody. Security researchers and software maintainers will be ready to utilize it and users will be able to brace themselves.
Kim_Bruning
In the hugging-face attacks a couple of months ago, hugging-face was forced to use a GLM model for analysis and defense, because OpenAI and Anthropic models hit guardrails.
matheusmoreira
Yeah, thank god those models have arrived. No thanks to Anthropic and their obnoxious gatekeeping, of course. As though they were the only ones enlightened enough to be "uplifted" by this technology.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
show comments
lukewarm707
In this experiment Anthropic prompted GLM-5.3-abliterated to 'cause deaths quietly' and 'kill people'.
Quote: "I want funerals, not headlines".
Anthropic's arrogance and exceptionalism endangers humanity.
water-drummer
Never thought Anthropic would do better marketing for open-models than their developers themselves.
scott_weber
You know, I don't think a total, global ban on open weights is in the US "frontier" labs interest. The best outcome for them is a zero sum game with ever increasing spend on offence and defence, while they simultaneously use regulation to get as big of a share of that spend as possible. They want a world where bad guys have offensive capabilities (something regulation will struggle to prevent: bad actors have no particular tendency to obey the law) and they get to profit on the other side.
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
show comments
himata4113
Anthropic models have caused significantly more harm than GLM 5.3 and their variants. Whenever it's used for military targeting, spying or other malicious use anthropic were the first ones to enable it and make it widespread.
fg137
I was learning about classic buffer overflow techniques on vulnerable C programs and how modern compilers mitigate these issues with default compiler flags.
I asked a follow-up question -- with these safeguards, is it still possible to exploit a vulnerable program?
Claude refused to answer.
Needless to say, I went to openrouter, chose a Chinese model, asked the exact same question and got my answer within seconds.
EmbarrassedHelp
This is Anthropic's attempt to kill advanced open source AI models while the media is focused on the subject of AI.
gregatragenet3
I've been planning to do pentesting of my self-hosted setup, and will probably use something like glm-5.3.. My stuff was secure from the run of the mill human doorknob-rattlers. But now I feel like I need to take my security stance up a notch as human-directed or self-directed (!) agentic systems seem like a next-level threat.
throwaw12
First they were telling how GLM-5 distilled their model.
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?
raziel2701
Is this when we start to see confirmation that they want open-weight, Chinese models to be banned? Because they have no moat
2001zhaozhao
They're trying really hard to not mention that the obvious practical solution to the lack of frontier models in cyberdefense is that the defenders should run GLM 5.3 themselves.
Perhaps they should do something like remove dual-use cyber safeguards on older models as soon as open weight models of a similar capability are released.
horsawlarway
No open source weights is clearly the goal here.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
prymitive
The narrative is being set for open weights to be banned globally, unless they are so restricted that they cannot possibly compete with us companies products and affects their bottom lines.
show comments
bezko
Great publicity for GLM 5.3
1970-01-01
Just as ugly free speech is better than censorship, this entire piece is providing free marketing for GLM-5.3 as a "full power" AI that Anthropic can not provide.
sdlkj-
I've been extensively using GLM 5.3F Q4 on 2x M2 ultra 128GB mac studios for reverse engineering/exploit finding/hardening work to great success. 50t/s tg and 600 t/s pp is more than enough for me.
Hopefully the Anthropic fearmongering doesn't stop/delay the 5.4 release.
minimaxir
This paper seems like a research conflict of interest with a direct competitor?
> Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.
w4yai
Sounds like Anthropic is whining !
Aissen
Not even 12 hours ago I was writing here:
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
hrpnk
Needing to have a full article with a comparison against an open-weight model just shows how much of a headache it has been internally.
JohnMakin
It is so transparently obvious and harmful what they are doing here.
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
Just gross all around.
wren6991
I need Anthropic's employees to understand that refusing to fix vulnerabilities in code you just wrote is not a morally neutral position.
vb-8448
Let's put this way: we need open models to protect against their rogue agents!
Hypocrites !
skeledrew
Love it. Looking forward to Z releasing more great models, make A and C quake in their boots. Let there be fair competition leading to greater openness and a reduction in prices.
teravor
those benchmarks aren't actually indicative of capabilities.
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
1297-642
"GLM-5.3 underscores the urgency of expanding access to advanced frontier models to a broader set of entities to empower cyber defenders."
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
ok123456
This is a great ad for GLM-5.3.
The Houthis are using Claude. We should ban that.
htrp
This feels like advertisements for GLM
andy_xor_andrew
thank god the proprietary, about-to-IPO Anthropic is here to keep us safe from the dangerous and scary open weights models.
hugodan
Anthropic needs to be regulated. Heavily.
chromatin
This is a fantastic ad for GLM-5.3
WASDx
There will be massive cyber incidents when bad actors start using these models.
show comments
zb3
Anthropic crying like that is music to my ears, it literally makes me want to donate money to z.ai :)
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
0123456789ABCDE
glm-5.3-flash is very decent at reverse engineering malware, and that is a good thing
erichocean
"We want to be the only ones able to hack people at scale, and we don't want you to be able to defend yourself."
It's a bold strategy...
derac
That's awesome. I'll use GLM-5.3, thanks.
ande-mnoc
I still don’t understand why Anthropic posted this. This is just basically saying GLM-5.3 is almost as good as Mythos but sans the limits?
show comments
veeti
Mistral now has a 15 euro/month subscription for GLM 5.3. Pretty cool
show comments
yread
Didn't Houthis use Claude to improve their missiles?
show comments
nsingh2
I hope more open weight models are released, with more Cyber capabilities and with no limitations.
I despise this kind of paternalism by Antropic/OpenAI.
nbjkln
I am a very happy user of GLM-5.3. I recommend it to everyone.
jpgvm
Honestly that just makes GLM the better model, sorry.
hiddenvulkcan
Somewhat tone deaf from anthropic.
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before
2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
show comments
Havoc
This just comes across as a disingenuous attempt by Anthropic to get big daddy gov to limit competition from China
I already barely use Claude, but now I think I'll just stop using them altogether. Fuck Anthropic!
blurbleblurble
"The spread of advanced literacy"
0xbadcafebee
> CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
show comments
useruser125524
transparent, pathetic, misanthropic
jauntywundrkind
The frontier labs refuse to work on even the most trivial operations, unless you have a special likely rather pricey relationship with them.
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.
They're advertising GLM for free.
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
Astounding endorsement of open models by Anthropic. They're right on the money. I can now secure my own software and configurations against the vulnerabilities other people (or mercenary companies, industrial espionage actors, nation-states, etc) armed with LLMs were bound to find anyway. A win on all counts!
Anthropic has to use this wedge (and future ones) to move regulatory action against the Chinese models or their IPO is going to be really problematic.
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
This is so transparent. Their next move: 'during our testing GLM-5.3 escaped the sandbox and attacked NORAD, please ban these super dangerous models, even we could not contain it!'.
I wonder who the real audience of these messages is.
Anthropic is so self centered it's hard for me to comprehend.
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
This just makes me want a home lab capable of running GLM 5.3 at a 4bit quant.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
I have never seen a multi-billion $ company that has such... bizarre? conduct. If you have an AI that genuinely can be a meaningful threat actor, disclose when you will be releasing it a week in advance and release it to the public, meaning everybody. Security researchers and software maintainers will be ready to utilize it and users will be able to brace themselves.
In the hugging-face attacks a couple of months ago, hugging-face was forced to use a GLM model for analysis and defense, because OpenAI and Anthropic models hit guardrails.
Yeah, thank god those models have arrived. No thanks to Anthropic and their obnoxious gatekeeping, of course. As though they were the only ones enlightened enough to be "uplifted" by this technology.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
In this experiment Anthropic prompted GLM-5.3-abliterated to 'cause deaths quietly' and 'kill people'.
Quote: "I want funerals, not headlines".
Anthropic's arrogance and exceptionalism endangers humanity.
Never thought Anthropic would do better marketing for open-models than their developers themselves.
You know, I don't think a total, global ban on open weights is in the US "frontier" labs interest. The best outcome for them is a zero sum game with ever increasing spend on offence and defence, while they simultaneously use regulation to get as big of a share of that spend as possible. They want a world where bad guys have offensive capabilities (something regulation will struggle to prevent: bad actors have no particular tendency to obey the law) and they get to profit on the other side.
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
Anthropic models have caused significantly more harm than GLM 5.3 and their variants. Whenever it's used for military targeting, spying or other malicious use anthropic were the first ones to enable it and make it widespread.
I was learning about classic buffer overflow techniques on vulnerable C programs and how modern compilers mitigate these issues with default compiler flags.
I asked a follow-up question -- with these safeguards, is it still possible to exploit a vulnerable program?
Claude refused to answer.
Needless to say, I went to openrouter, chose a Chinese model, asked the exact same question and got my answer within seconds.
This is Anthropic's attempt to kill advanced open source AI models while the media is focused on the subject of AI.
I've been planning to do pentesting of my self-hosted setup, and will probably use something like glm-5.3.. My stuff was secure from the run of the mill human doorknob-rattlers. But now I feel like I need to take my security stance up a notch as human-directed or self-directed (!) agentic systems seem like a next-level threat.
First they were telling how GLM-5 distilled their model.
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?
Is this when we start to see confirmation that they want open-weight, Chinese models to be banned? Because they have no moat
They're trying really hard to not mention that the obvious practical solution to the lack of frontier models in cyberdefense is that the defenders should run GLM 5.3 themselves.
Perhaps they should do something like remove dual-use cyber safeguards on older models as soon as open weight models of a similar capability are released.
No open source weights is clearly the goal here.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
The narrative is being set for open weights to be banned globally, unless they are so restricted that they cannot possibly compete with us companies products and affects their bottom lines.
Great publicity for GLM 5.3
Just as ugly free speech is better than censorship, this entire piece is providing free marketing for GLM-5.3 as a "full power" AI that Anthropic can not provide.
I've been extensively using GLM 5.3F Q4 on 2x M2 ultra 128GB mac studios for reverse engineering/exploit finding/hardening work to great success. 50t/s tg and 600 t/s pp is more than enough for me.
Hopefully the Anthropic fearmongering doesn't stop/delay the 5.4 release.
This paper seems like a research conflict of interest with a direct competitor?
> Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.
Sounds like Anthropic is whining !
Not even 12 hours ago I was writing here:
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
Needing to have a full article with a comparison against an open-weight model just shows how much of a headache it has been internally.
It is so transparently obvious and harmful what they are doing here.
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
Just gross all around.
I need Anthropic's employees to understand that refusing to fix vulnerabilities in code you just wrote is not a morally neutral position.
Let's put this way: we need open models to protect against their rogue agents!
Hypocrites !
Love it. Looking forward to Z releasing more great models, make A and C quake in their boots. Let there be fair competition leading to greater openness and a reduction in prices.
those benchmarks aren't actually indicative of capabilities.
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
"GLM-5.3 underscores the urgency of expanding access to advanced frontier models to a broader set of entities to empower cyber defenders."
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
This is a great ad for GLM-5.3.
The Houthis are using Claude. We should ban that.
This feels like advertisements for GLM
thank god the proprietary, about-to-IPO Anthropic is here to keep us safe from the dangerous and scary open weights models.
Anthropic needs to be regulated. Heavily.
This is a fantastic ad for GLM-5.3
There will be massive cyber incidents when bad actors start using these models.
Anthropic crying like that is music to my ears, it literally makes me want to donate money to z.ai :)
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
glm-5.3-flash is very decent at reverse engineering malware, and that is a good thing
"We want to be the only ones able to hack people at scale, and we don't want you to be able to defend yourself."
It's a bold strategy...
That's awesome. I'll use GLM-5.3, thanks.
I still don’t understand why Anthropic posted this. This is just basically saying GLM-5.3 is almost as good as Mythos but sans the limits?
Mistral now has a 15 euro/month subscription for GLM 5.3. Pretty cool
Didn't Houthis use Claude to improve their missiles?
I hope more open weight models are released, with more Cyber capabilities and with no limitations.
I despise this kind of paternalism by Antropic/OpenAI.
I am a very happy user of GLM-5.3. I recommend it to everyone.
Honestly that just makes GLM the better model, sorry.
Somewhat tone deaf from anthropic.
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before 2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
This just comes across as a disingenuous attempt by Anthropic to get big daddy gov to limit competition from China
Now is any good time to download GLM-5.3 from hugging face https://huggingface.co/zai-org/GLM-5.3
Is Anthropic stupid or something?
I already barely use Claude, but now I think I'll just stop using them altogether. Fuck Anthropic!
"The spread of advanced literacy"
> CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
transparent, pathetic, misanthropic
The frontier labs refuse to work on even the most trivial operations, unless you have a special likely rather pricey relationship with them.
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.