Chinese AI developer Zhipu launched GLM-5.3 last week, claiming the model matches American AI systems in detecting software vulnerabilities. According to benchmark testing, GLM-5.3 outperformed competing models on CyberGym, a standard test measuring AI ability to solve real-world cybersecurity challenges. The company reports the model excels particularly at reasoning across multiple exploitation stages rather than simply identifying isolated flaws.
Zhipu tested GLM-5.3 on actual production codebases in partnership with Chinese companies, discovering 2,436 vulnerabilities across 269 projects. The findings included 1,097 medium-to-high severity issues spanning system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. Some vulnerabilities had existed undetected for decades, with the oldest dating back approximately 40 years.
The model demonstrated what Zhipu calls accelerated development of cyber capabilities during post-training scaling. Rather than becoming merely better at spotting individual security flaws, GLM-5.3 developed the ability to form coherent plans for complete exploitation chains. This represents a significant advancement in AI-assisted vulnerability research, though the model performed less well than Western alternatives on other security and coding benchmarks.
The release signals China has rapidly narrowed the technology gap with American AI developers in cybersecurity applications. This capability emerged quickly following Anthropic's release of similar technology, suggesting any perceived US advantage in this domain has largely disappeared. The development gives Chinese entities sophisticated tools for analyzing software security in both domestic and foreign systems.
Security teams should recognize that AI-powered vulnerability discovery tools are becoming widely available across geopolitical boundaries. Organizations relying on obscurity or assuming vulnerabilities in legacy code will remain undetected face increased risk. Regular security audits of older codebases and accelerated patching cycles become more critical as AI models demonstrate ability to uncover long-hidden flaws at scale.
Source: https://www.theregister.com/security/2026/08/17/chinese-ai-company-zhipu-claims-its-new-model-is-a-better-bug-finder-than-anthropic-openai/5288203


