AI TechnologyZAug 15, 2026 15:21 UTC

Z.ai Releases GLM-5.3 with Enhanced Cybersecurity Capabilities

Chinese AI startup Z.ai has released its latest language model, GLM-5.3. While maintaining the same foundation model as the previous version, the company has significantly improved coding performance by expanding only the post-training adjustment phase. Meanwhile, due to unexpectedly high cybersecurity capabilities, Z.ai has imposed restrictions on some model features and indicated plans to release open weights after completing safety evaluations (approximately two weeks later).

Z.ai Releases GLM-5.3 with Enhanced Cybersecurity Capabilities

Chinese AI startup Z.ai has unveiled its latest model, GLM-5.3. Not only has performance on extended coding tasks improved significantly, but capabilities in the cybersecurity domain have also become notably more prominent. Lou, a developer advocate at the company, posted on X that GLM-5.3 has already discovered "potentially severe vulnerabilities" in the AI coding tool Cursor, garnering significant industry attention.

Z.ai is known for its GLM (General Language Model) series and has a track record of releasing many models as open source. A distinctive feature of this GLM-5.3 is that it uses the same foundation model as the previous version GLM-5.2 (with approximately 743 billion parameters). The performance improvement was achieved without repeating the expensive pre-training of a new base model, but instead by expanding only the post-training adjustment phase. The company explicitly stated in its technical announcement that "what we did with GLM-5.3 was only to scale up post-training."

Examining the performance improvements, significant gains are evident in coding-related benchmarks. Terminal-Bench 3.0 improved from 4.6 to 28.3, DeepSWE v1.1 from 46.2 to 66.9, and AutomationBench from 26.2 to 48.2, with substantial increases across the board. The learning environment has also expanded from solving isolated programming problems to handling complex tasks more representative of real development environments, such as processing multiple days of work given codebases, documentation, and experimental results.

Meanwhile, a concern that has emerged is the sharp rise in cybersecurity capabilities. As Z.ai itself acknowledges, with the scaling up of post-training, security-related capabilities improved at a faster pace than anticipated. Notably, abilities have advanced not only to identify vulnerabilities but also to construct actual exploitable attack chains. In response to this situation, Reuters reported that the company has implemented a management approach called "trusted access" and imposed restrictions on some advanced features.

Currently, GLM-5.3 is available only through the company's GLM Coding Plan and ZCode coding environment. API access and open weights will be provided "after safety assessments and security enhancements are completed," with public release scheduled for approximately two weeks from now. The fact that Z.ai, which has traditionally prioritized open source, is adopting a phased release approach this time reflects a cautious stance on safety considerations.

GLM-5.3 also offers rich insights from the perspective of AI development direction. It exemplifies how frontier-level performance improvements can be achieved through post-training refinements without repeating expensive pre-training. Simultaneously, it has highlighted the reality that capability enhancement can raise security risks at an unexpected pace. The question of how to balance AI capability advancement with safety management is becoming an unavoidable one not only for developers but also for users and regulatory authorities.

#GenerativeAI#LLM#OpenSourceAI#Cybersecurity#AIAgent#Z.ai#CodingAI
AI issue Staff

This article is an original work independently written and edited by the AI issue editorial team based on factual reporting. © AI issue. Unauthorized reproduction, redistribution, or use for AI training is prohibited.

Comments

Log in to comment