Z.ai says GLM-5.3 nears Anthropic in cyber defense as coding gains accelerate
Chinese AI company Z.ai has released GLM-5.3, a new model that can match or edge some leading US models in identifying software vulnerabilities and narrowing the gap with Anthropic on long-running coding tasks.
Intelligence analysis by Llama

Z.ai's GLM-5.3 model has shown strong results in coding and cybersecurity benchmarks, with a 50% improvement in coding performance and a 200% increase in ExploitBench score compared to its predecessor GLM-5.2.
Imagine you have a super smart robot that can write code and find bugs in it. Z.ai's new model, GLM-5.3, is like that robot, but it's even better at finding bugs and fixing them. It's like having a team of expert programmers working for you, but instead of being human, it's a computer program.
Analysis
GLM-5.3's Cyber Defense Capabilities
Z.ai's GLM-5.3 model has shown impressive results in cyber defense, with a 54.4% score on ExploitBench, compared to 78.0% for Anthropic's Mythos 5. However, Mythos 5 remains well ahead when the task shifts from finding a flaw to building a working exploit. Z.ai's GLM-5.3 scored 84.5% on CyberGym, which tests whether a model can inspect source code, find vulnerabilities, and verify them, slightly ahead of Anthropic's Mythos 5 at 83.8% and OpenAI's GPT-5.6 Sol at 83.6%. The company's focus on building a model that can work like an autonomous software engineer has led to emergent cyber capabilities, which serve as both a new selling point and a test of Z.ai's broader idea.
Z.ai's Post-Training Approach
Z.ai's GLM-5.3 model uses the same base model as its predecessor, GLM-5.2, with the company attributing the improvement entirely to post-training, or the work performed after a foundation model completes its main pretraining run. This makes GLM-5.3 less a jump to a larger foundation model and more a test of how far Z.ai can improve an existing one by training it in longer and more realistic software engineering environments. The company's post-training approach has led to significant gains in coding performance and cybersecurity, with a 50% improvement in coding performance and a 200% increase in ExploitBench score compared to GLM-5.2.
Z.ai's Future Plans
Z.ai has not yet released the model weights that would allow developers to download and run GLM-5.3 independently. The company said it would delay the public release for about two weeks while carrying out more security checks and strengthening safeguards. Its most sensitive cybersecurity functions will initially be limited to selected partners and verified users under a 'trusted access' program.
Key points
- Z.ai's GLM-5.3 model has shown strong results in coding and cybersecurity benchmarks.
- The model uses the same base model as its predecessor, GLM-5.2, with the company attributing the improvement entirely to post-training.
- GLM-5.3 has a 50% improvement in coding performance and a 200% increase in ExploitBench score compared to GLM-5.2.
- The company has not yet released the model weights that would allow developers to download and run GLM-5.3 independently.
- Z.ai's most sensitive cybersecurity functions will initially be limited to selected partners and verified users under a 'trusted access' program.
If GLM-5.3 continues to improve, it could lead to significant advancements in cyber defense and software engineering. This could have a positive impact on the tech industry, making it easier to develop secure software and protect against cyber threats.
However, the development of GLM-5.3 also raises concerns about the potential misuse of AI in cyber attacks. If the model is not properly secured, it could be used to launch more sophisticated cyber attacks, which could have serious consequences.



