Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
Interesting play before an IPO...
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).
I really don't think people fully appreciate why anthropic was founded.
Looks like Anthropic is moving on from ridiculing Open Weight to wanting to Burn them.
GLM-5.3 flash has been great for us and I am going to now invest serious effort in evaluating the full fat GLM-5.3 given this ringing endorsement.
Interestingly Z.ai does not train on user prompts, unlike Anthropic. (source: https://openrouter.ai/z-ai/glm-5.3#providers )
if models can find and exploit bugs this fast, anything sitting on a public IP is going to get tested harder and faster.
soon, you'll just have to live under the assumption that an attacker could theoretically get into your infra - so all your precautions will need to have that as a baseline
hence, betting on "undiscoverable resources" as the next big enterprise push!
There is a very dangerous thing that is very capable and available to everyone. Cranks the volume to 100% AND IT'S JUST 20% OF OUR PRICE, HURRY UP AND TRY IT.
I previously successfully used GLM 5.3 to find out how our DRM system gets bypassed, and Mythos isn't available to me...
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
There was this incident that seemingly flew under the radar (52 days ago): https://news.ycombinator.com/item?id=49216185
6 months ago: https://news.ycombinator.com/item?id=47288552
This one also flew under the radar
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
https://www.goodreads.com/quotes/7515521-william-roper-so-no...
It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.
The only open models that are "almost as good or better in some cases" require massive amounts of RAM. I posit that most people cannot afford a decked out Mac Studio, and therefore run the smaller "flash" variants on more normal devices. The issue is that those are nowhere near frontier-level in terms of capability.
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
Anthropic has been telling everyone that these models are dangerous. OpenAI and Anthropic failed to contain their tests.
Given the history, this testing is extremely reckless. I think it is criminal, it endangers others.
Anthropic has no authority here and they are going too far. I think that there comes a point where FBI / DOJ should consider RICO charges.
That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.
In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.
For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.
Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.
Also, there exists a $750 GPU (V100) that can run 4-bit 27B quant at >90 t/s. And I find it far from useless. It is not the most capable model, but when you just need to offload and rip through assembly and you have chores batched up, it's pretty good. I use Qwen Flash Next at a 3-bit quantization, point it at disassembly with goals, put it in a harness with auto-compaction and a loop, and let it rip. Sometimes I wake up, and it’s just hilariously off. Other times, it completely accomplished the goal. I have one Qwen Flash Next 3.8 running right now, and 2x27B on a 4bit quant as workers, and they stay busy. This was not possible with local models on this level of hardware even two months ago.
I have Qwen Flash Next at >100 t/s. Things have never been better for local models.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
+100.
Thanks God. these open weight models exist.
And the fact Anthropic is currently trying lobby against these models is despicable.
There is no scenario where putting the key of cybersecurity in the hands of few chosen ones is even remotely acceptable.
No government, no company, no entity should have this power.
Soon or later it will be abused (By 3 letter agency or by an insider/leak).
Delayed disclosure is dead already.
So just give the same capabilities to everybody and stop to fuck around.
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
Tip: If someone was spending billions of dollars figuring out how to equip your Glock to stand up, unlock a door, walk around, talk to people, and make decisions... it would be dangerous.
Explained further here: https://news.ycombinator.com/item?id=49094348
Though there is further nuance in agentic vs non-agentic AI: https://news.ycombinator.com/item?id=49736149
> There will be new adversarial games when everyone's smarter (bio/cyber offense/defense), but those games are always symmetrical in the long run
This is an article of faith, not an argument.
This is not faith, but an observation of Earth's past. If it were the case that intelligence is itself harmful, then it should not have evolved in so many species.
And even if we look at only humans, we do not see dumber populations being more prosperous. One could argue about the definition of "dumber" and "prosperous", but it is at least true in my own judgement of value, which I suspect is not too far from the average in modern society. One could also argue that bio/cyber adversarial games are qualitatively different from all past adversarial games, but you could argue the same thing for other qualitatively different games that emerged in the past, when they were new. But we're still here. So this argument hinges on burden of proof, and I think that's on Anthropic.
Also, as mentioned in that first linked comment, centralizing AI development increases a different kind of speciation risk: a small group of superintelligent humans, likely the ones currently running the top AI companies, splitting from the rest of humanity.
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
The second any one of them wins, oppression the likes of which we cannot even imagine will follow.
Well, kinda thanks to Anthropic, what with the distillations.
https://www.lesswrong.com/posts/Jc9YZEmqHgocAKiaH/does-disti...
Quote: "I want funerals, not headlines".
Anthropic's arrogance and exceptionalism endangers humanity.
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
I wonder who the real audience of these messages is.
Perhaps they should do something like remove dual-use cyber safeguards on older models as soon as open weight models of a similar capability are released.
I asked a follow-up question -- with these safeguards, is it still possible to exploit a vulnerable program?
Claude refused to answer.
Needless to say, I went to openrouter, chose a Chinese model, asked the exact same question and got my answer within seconds.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
> Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
Hopefully the Anthropic fearmongering doesn't stop/delay the 5.4 release.
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
Just gross all around.
Hypocrites !
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
It's a bold strategy...
[0]: https://www.theguardian.com/technology/2026/mar/01/claude-an...
I despise this kind of paternalism by Antropic/OpenAI.
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before 2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
I expect Google to swallow first, followed not long after by Apple.
I already barely use Claude, but now I think I'll just stop using them altogether. Fuck Anthropic!
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
So thankful that these open models exist.
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.