"The way that Hugging Face defended itself was with an open source Chinese model, GLM, because they didn’t have access to the high cybersecurity models on the other side. They’re too dangerous."
This is not what happened. HuggingFace patched the vulnerabilities in the ordinary way, then used GLM for some of the forensic analysis afterwards. It's in the interest of HF to promote the GLM part of the story, because it emphasizes their agency in the situation as well as the open-source models they distribute. But GLM was a (useful) part of the postmortem, not of the defense.