August 23, 2026

AIincider

AI News. No Noise. Just Signal.

Z.ai Holds Back GLM-5.3 Weights Over Hacking Skills

2 min read
Z.ai shipped GLM-5.3 but is holding its open weights back after the model found 1,097 critical bugs. Here is why the delay matters. Read on.

An open-weight AI model built for coding turned out to be so good at finding software vulnerabilities that its own developers decided not to release it on schedule. Z.ai announced GLM-5.3 on August 14 and, in the same breath, said the weights would stay private for roughly two weeks of additional safety work.

What GLM-5.3 Found

Open weights mean a model’s parameters are published for anyone to download, run locally and modify. That openness is how Chinese labs have won developer share against closed American systems, and Z.ai, formerly Zhipu AI, has been one of its loudest champions. Holding weights back is not a small reversal for a company built on shipping them.

During evaluation, GLM-5.3 surfaced 2,436 vulnerabilities across 269 open-source projects. Of those, 1,097 were rated critical or high severity, including bugs in Linux, WebKit and FreeBSD, three pieces of software that sit underneath a very large share of the internet.

The Benchmarks Behind the Delay

On CyberGym, which scores how reliably a model locates known vulnerabilities in source code, the model hit 84.5 percent, up from 77.2 percent for GLM-5.2. The bigger jump came on ExploitBench, which measures exploit reasoning rather than detection: 54.4 percent against 24.4 percent for the previous version. That is more than double in a single generation.

Z.ai’s own framing is the striking part. The company said the model’s cybersecurity capability grew past what the training run was designed to produce. Selected security partners keep controlled access while the review continues.

Why It Matters

A tool that finds critical bugs at this rate is enormously valuable to defenders, who can patch before anyone else notices. It is equally valuable to attackers, and once weights are public there is no way to give one group access and not the other. Closed labs manage that tension with rate limits and account bans. Open-weight labs have exactly one lever: whether to publish at all.

That makes this delay a useful precedent and a fragile one. It also lands as Chinese regulators reportedly weigh curbing foreign access to the country’s most capable models, which would turn a voluntary pause into policy.

Watch the release date. If the weights ship near the end of August as planned, a two-week safety hold becomes a template other labs can copy.

Continue Reading…

Leave a Reply