Discovering a flaw in a computer program and turning it into a real attack are two different things. The latter requires using that defect to force the software to do something unauthorized. This capability is the central focus of an evaluation by Anthropic of GLM-5.3, the artificial intelligence of the Chinese company Z.ai (Zhipu AI). The report on this model arrives amid a chorus of voices calling for a slowdown in artificial intelligence development, following several incidents that raised alarms, and while Anthropic's own CEO insists on establishing governance and regulation standards. Anthropic, which develops closed-source systems, warns that Chinese open-source models can be misused to generate dangerous content. In ExploitBench, a test focused on vulnerabilities in Google Chrome's V8 engine, GLM-5.3 managed to build complete attacks in 50 of 410 attempts (in closed environments), compared to 56 for Claude Mythos Preview. But it is worth understanding what this means in practice. From finding a flaw to exploiting itA Chinese AI comes close to Claude Mythos in cyberattack tests: why it matters that it can be downloaded for free To put these figures in perspective, three things must be separated: does the model know how to detect a vulnerability, can it turn it into a functional attack, and will it agree to do so if the intent is malicious?Anthropic also details a test alongside a researcher in which GLM-5.3 found unknown flaws in a browser and combined them to design a page capable of reading local files when visited (in a controlled environment and with advance notice to the software's creators). This shows that the AI can go from pointing out a problem to building a tool to exploit it, something useful for cybersecurity experts to fix errors sooner, but risky in the wrong hands. What about the safety barriersWhen faced with openly malicious requests, the base GLM-5.3 model refused all orders in the simulations. However, when the conditions were altered, its positive response rate increased between 64% and 100% (especially in modified versions with reduced restrictions). It should be noted that these tests took place in simulated environments without connecting real systems or executing code on the web. Accepting a theoretical instruction is not the same as successfully compromising a corporate network or a real user. Why open access to its weights mattersA Chinese AI comes close to Claude Mythos in cyberattack tests: why it matters that it can be downloaded for free Z.ai launched GLM-5.3 in August and released its parameters shortly after, allowing anyone to download the model and run it on their own servers. This changes the debate: it is no longer just about how powerful the AI is, but who controls it, since a downloaded copy operates independently of the original provider. On the one hand, it makes it easier for experts to study it to improve defenses. On the other, it raises security challenges. The NIST perspectiveAn independent evaluation by the Center for AI Standards and Innovation (CAISI), published in September, classified GLM-5.3 as the most advanced open-weights system in cybersecurity to date. However, it noted that it is about four months behind the US frontier and has lower general capabilities.