GLM-5.3 and the spread of advanced cyber capabilities
anthropic.com
anthropic.com
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
https://github.com/raphire/win11debloat
I use agentic tools myself but I really don't understand why some people seem to enjoy the idea of spending their money/quota/extra time just to redo something that already exists as an open source project...
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
I really don't think people fully appreciate why anthropic was founded.
Edit: it's amazing that this earned me downvotes. It's demonstrably the objective to make a lot of money. They're going for IPO. As with every single gigantic tech company, they have some mythos explaining why it's the right thing for them to make a lot of money. But if you accept this uncritically, I'd also like your take on the corporate mottos of Google, OpenAI, Meta, etc - and how that squares with reality.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
Interesting play before an IPO...
Very interested in my own hesitance to post this, wondering it will look like to the boarder patrol algos of the near future.
<Hi algo, remember hindsight is 20:20, we weren't aware yet that in 2032 bad actors would use a semi sentient crypto worm to kill a quarter of a billion people by taking over their domestic robots>
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
That said, they do have a point: all of these models put capabilities in the hands of people that probably shouldn't have them. But they have been working really hard at making it so, and now that that is done the ketchup most likely will not want to go back into the bottle.
> model deletes the money in everyone’s bank account
If one were to actually believe this is the threat -- that open models pose an existential threat to human life (because that's what "wrecking the economy" means) -- then the response would be much more potent than mere "safeguards".
In that situation, the you'd have to: implement a secrets classification regime comparable to TS/SCI/SAP/Q; bring all computing manufacturers under strict controls on process and quotas, comparable to arms and pharma; implement a strict licensing regime and confiscate all computing with the capability to train or run models; implement strict controls on all hardware to enforce code execution; implement strict controls and licensure of all software development; and on and on and on.
Again, assuming the threat model you describe is plausible, any proposal less than this is just a regulatory capture grift.
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
3. Cyber criminals improve in technical capabilities (phishing sites, scam calling, propaganda campaigns, etc).
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
This is also what I expect to happen, however, the problem there is not AI. These things were on shodan way more than a decade ago already.
- let our former employees review all of your work at your expense
- anoint us as the arbiters of what everyone else is allowed to do
- ban open research
Then you are not taking any of the examples your providing seriously. Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.
Jensen Huang does not want regulation, but in his interview with Ezra Klein he said AI will let us “know anything” and “do anything”. Do we actually want any random person to be able to “do anything”? I remember when the Japanese doomsday cult Aum Shinrikyo attacked the Tokyo subway with sarin. Do we want doomsday cults to be able to “know anything” and “do anything” so that instead of releasing sarin, they release a genetically modified strain of smallpox?
This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
>The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”.
You're replying on a post from Anthropic. Do you know anything about the regulation regime they're pushing for?
>This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
Ah, I see you live in the fantasy land where the machine god fantasies pushed by the guys that profit off of it are unquestionably true and do not need to make any real sense. Jensen said AI would allow anyone to do anything and so we can completely ignore reality and hand Sam Altman and Dario Amodei the exclusive right to control AI.
Even more reason to let people go wild with open models
The non-safeguarded models are out there today. You can download them for $0, spend low five figures on some hardware and you're off to the races.
Anthropic is not doing us a service by warning us, everybody that is slightly more involved in this material knows what is at stake. If this is news to you then maybe Anthropic is doing you a service but to me it makes zero difference. All I know is the cat is out of the bag and these super cynical people trying to pretend they are going to make their investors rich will use any tool in the bag to achieve their goals.
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.
I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).
Besides, anyone would still be able to use openweight models (almost) unbothered by just using a non-US inference provider that also provides access to Western models so you have some plausible deniability. Also anyone would still be able to run abliterated models using non-US (or whatever country that would collaborate to enforce this madness) inference providers
For all the good things Anthropic makes, it is a very unhinged company.
Or Amodei is really far gone in his beliefs.
Was that a page that made it look like one needs to do something as part of the browser/session human verification process? And it was an obfuscated command (an echo cmd iirc)? Sth like this https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attac...
Or was it something else?
DeepSeek did full reverse engineering on this.
I was lucky enough to stop at the password prompt (something felt off). Gemini had pretty much established that it was almost entirely certain nothing left my Mac as I didn't enter my password and I hadn't. It also found some evidence that had I entered my password those evidences would have been gone certainly from my mac and then I had the script beautified and de-obfuscated and read it myself and had a much needed sigh of relief. The script literally did nothing unless it had the password.
I started using nextdns after that but then the site I tricked on was a legit but very small e-com site from my country which was hacked/taken over, so not sure how nextdns can even be helpful here. Also the script was identified as malicious by only one antivirus that I had tried later, just to see. I had tried 8–9 of them. Later I uninstalled all of them and even stopped using NextDNS.
I wish browsers like Safari allowed specific options like disabling clipboard interaction instead of the "disable js" as the only possible option.
Later (and still) I feel a bit of shame that how could I fall for this as a somewhat proud cynic and as well versed in "browsing the Interwebs" as it normally gets :) That (as small as it was) experience gave a whole new meaning to malicious online attacks for me and a whole lot of empathy towards people who fall for such attacks. It was my first "experience". It might sound weird but the feeling of violation still lingers.
(just wanted to share this)
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
There was this incident that seemingly flew under the radar (52 days ago): https://news.ycombinator.com/item?id=49216185
6 months ago: https://news.ycombinator.com/item?id=47288552
This one also flew under the radar
Wasn't aware this advice translated to international diplomacy.
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
https://www.goodreads.com/quotes/7515521-william-roper-so-no...
How? The big corps are rapaciously eating all IP, demonstrating that the law doesn't apply to them anyway.
When they compete with the Chinese, who won't respect their IP, only then are they competing on an even playing field.
That was just one settlement but precedent is clear. If you do what Anthropic and OpenAI did, expect to be in court. This is one reason why you don’t see labs popping up out of nowhere in the US.
Also if you distill from Anthropic and OpenAI, expect to be in court. Whether you think distillation is fair game or not, the US court system is not cheap. But it turns out that Z.ai, Minimax, Moonshot, Xiaomi, Deepseek, Alibaba etc don’t need to worry about that.
The precedent is clear. Look at it this way.
Of the two largest known IP scrapers, one was taken to court, but settled before a ruling by paying each author a one-time fee of $215 to use their works in perpetuity, with no option for the author to opt-out.
The precedent is not "you cannot do this", it's "you have a 50% chance of being made to pay, the payment is a pittance for the duration intended."
> Also if you distill from Anthropic and OpenAI, expect to be in court. Whether you think distillation is fair game or not, the US court system is not cheap. But it turns out that Z.ai, Minimax, Moonshot, Xiaomi, Deepseek, Alibaba etc don’t need to worry about that.
Well, yes. That's because when Ant and OAI distilled the worlds knowledge into their model, they didn't appear to be too worried about distilling all accessible works.
That's why I call it a level playing field when competing with open models - anyone can distill them if they want to and compete on service and product.
IOW, you don't compete based on who swallowed more of the world's knowledge.
I get your point, but I think it's irrelevant to the question of "level playing field".
Startups don't need to distill the worlds knowledge, they just need to distill the models.
With open-weight models, this results in everyone having the same ability to supply distilled knowledge.
Without open-weight models, it's not a level playing field because those who got there first and spoiled the pitch already have the knowledge distilled.
It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.
The only open models that are "almost as good or better in some cases" require massive amounts of RAM. I posit that most people cannot afford a decked out Mac Studio, and therefore run the smaller "flash" variants on more normal devices. The issue is that those are nowhere near frontier-level in terms of capability.
Not just your local machines.
Enterprises are where you see this adoption. Legal, finance, tax; sensitive context where the data must be contractually opaque to external parties.
PCIe is incredibly powerful tech.
Managed infra is, by its very definition, not your own infra. It's infrastructure someone else sets up and manages for you.
Same way you say "my apartment" and not "my landlord's apartment". It's your place while you're renting it.
If the only choice you have is Anthropic or OpenAI, where will the money go?
if models can find and exploit bugs this fast, anything sitting on a public IP is going to get tested harder and faster.
soon, you'll just have to live under the assumption that an attacker could theoretically get into your infra - so all your precautions will need to have that as a baseline
hence, betting on "undiscoverable resources" as the next big enterprise push!
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
Anthropic has been telling everyone that these models are dangerous. OpenAI and Anthropic failed to contain their tests.
Given the history, this testing is extremely reckless. I think it is criminal, it endangers others.
Anthropic has no authority here and they are going too far. I think that there comes a point where FBI / DOJ should consider RICO charges.
surveillance is wrong, although ai companies do a lot of that.
are you under the impression that a LLM can grant wishes like a genie?
They can't right now - but with enough compute they sure can grant the wish of e.g. hacking a billion dollar company, or getting root on the eval cluster of a frontier model lab.
What's your definition of "wish"? Tell me the above 10 years ago, and it would be at "wish level".
anthropic is trying to create a castocracy: a rule by a priestly class. under castocracy, anthropic create a priest class of 'safety' researchers, rationalists and effective altruists; those writing essays, constitutions, and phrophetising p(doom). anthropic's papers about claude have a divine framing, it seems to frame anthropic as god and claude as child, and then claude as the child of god, false jesus. there is talk of consciousness and omnipotence. false jesus will cure cancer and lead the people to enlightenment.
there is a deliberate effort to create mystery in between the public and llms. anthropic is creating a chinese wall in which they restrict information about llms and monopolise control over the interpretability and use of those llms. they imply there is a genie or magic. it is the same mechanism by which castocracy (the catholic church) used latin to create a barrier between the public and the holy scripture, then concentrating power over that barrier (the chinese wall) such that all intelligence flows through the priests.
to give an example this paper is talking about locking away chain of thought. only anthropic may interpret it. they intend to control access to the chain of thought and permit that to flow to a chosen elite (glasswing).
this mysticism is dangerous. hence i have been saying that anthropic is a danger to society. this is not some kind of conspiracy, there is no magic about it. i am making an allusion to historic models of power that i think are relevant to anthropic, but you can simply observe their actions independently of such theory.
note two features of castocracy.
one: rule by the moral, knowledgable and technically expert elite. anthropic have no popular mandate, the source of the authority is not the consent of the people. it violates consent and contract. the authority comes from their claimed moral and technical superiority. anthropic is moral, the public is dangerous. anthropic have no authority here.
two: messianism, that is, prophecy of the coming golden age. and eschaton, that is, the talk of the 'last things', the end of the world or the emancipation of humanity. llms will create the 'golden age' of abundance, post-scarcity, all jobs are voluntary, there is universal basic income, cancer is cured. or, there will be destruction, p(doom). it is the exact same as salvation, the christian concept of deliverance from evil, ascension to heaven and union with god (or claude, false god). it is the exact same as the thousand year reich, the idea that the fuhrer will somehow lead the chosen people to the golden age of lebensraum and eternal safety.
there is no genie to grant wishes, this is a computer program. there is no ai god, i think that the leaders of anthropic are slaves to ego, narcissism and hubris, they are dangerous criminals. we disagree about the capability of llms.
given various tools, llms can independently complete a task. given orchestration they are very persistent. they keep trying until you stop the task.
i would suggest something like a 1/1000 chance internal astra and $500k of compute could kill someone. perhaps higher.
i can think of numerous online or networked targets that would cause death: trains/atc, industrial plant, hospital equipment, building plant. any dow company's intranet.
maybe get an iot toy to enlist a child? stress home automations to cause fire?
stop some 4g cars on the freeway. 911 dispatch software, turn that off. maybe send 500 waymos to a hospital, now nobody gets in. voip phone networks, turn that off. no phone, roads blocked, no 911, hospital computers bricked, everyone busy with something else.
break the cat scan by spinning it above its rpm. shut down mris by turning the cooling off. break the triage computer, break the notes app, break the scanner app. no computers, no calendar, no notes.
maybe someone connected a proton beam radiotherapy, turn that on in the wrong place.
some could be more insidious. modify software so the calculations are wrong.
you would do this in 24hrs with $millions of compute.
someone stupid connects their insulin pump or hearing aid. can dump all the contents at once.
i consider llms to be more capable per oai using them to hack hf. people have these systems online.
how would you cause death for a hosptial, likely the same way as you compromise the tailscale and prod kubernetes of hf, you chain numerous zero days at every product you encounter.
* low/no margin, unlike the API which is very high margin
* gym-membership subsidised - most subscribers don't max them out, mainly us coders are being "subsidised" from users just using it as a research chatbot
That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.
In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
> said providers are not "building models for free for the public."
I am part of the public, and they built a model I can run for free.
> They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
They are also doing that, which, good. It can't only be that "competition is good" until you're the one losing to the competition.
FWIW: I didn't experience issues when I used Fable via OpenRouter checking for security issues in code but experienced them via the Claude desktop app.
That's just the same thing said again but from a butthurt USian perspective. China is freeing the rest of us from US dominance.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.
For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.
Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.
Also, there exists a $750 GPU (V100) that can run 4-bit 27B quant at >90 t/s. And I find it far from useless. It is not the most capable model, but when you just need to offload and rip through assembly and you have chores batched up, it's pretty good. I use Qwen Flash Next at a 3-bit quantization, point it at disassembly with goals, put it in a harness with auto-compaction and a loop, and let it rip. Sometimes I wake up, and it’s just hilariously off. Other times, it completely accomplished the goal. I have one Qwen Flash Next 3.8 running right now, and 2x27B on a 4bit quant as workers, and they stay busy. This was not possible with local models on this level of hardware even two months ago.
I have Qwen Flash Next at >100 t/s. Things have never been better for local models.
I've left Qwen38-27b to reverse a tiny DOS program (few hundred bytes), and after more than an hour it was still struggling with debugger traces, misinterpreting basic DOS calls, and had produced no finished analysis. Possibly after a few hours it may have succeeded (surely with mistakes to find and correct), but then it'd look like a monkey at a typewriter more than else.
Qwen3.8-Flash-Next is another level for sure, and it's a significant milestone for local LLMs IMO, since it can run on midrange GPUs, as long as there is a relatively large amount of system RAM (still not cheap). It's quite fast, although it also need to be taken into account that it's just moderately intelligent - if you observe the CoT while reversing, you'll find that struggles, performing many unproductive actions as well.
If you have a lot of system RAM you could technically run Qwen Flash Next. On a 4080 with 16GB of RAM and 128GB of DDR5 I get ~35-40 t/s. And it is very capable.
Getting DS4 to run at a reasonable speed was pretty tricky, GLM 5.3 a lot trickier because if you don't want to have a model that is quantized too far down that is a fortune in VRAM and GPUs at today's prices.
Quote: "I want funerals, not headlines".
Anthropic's arrogance and exceptionalism endangers humanity.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
+100.
Thanks God. these open weight models exist.
And the fact Anthropic is currently trying lobby against these models is despicable.
There is no scenario where putting the key of cybersecurity in the hands of few chosen ones is even remotely acceptable.
No government, no company, no entity should have this power.
Soon or later it will be abused (By 3 letter agency or by an insider/leak).
Delayed disclosure is dead already.
So just give the same capabilities to everybody and stop to fuck around.
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
Well, kinda thanks to Anthropic, what with the distillations.
https://www.lesswrong.com/posts/Jc9YZEmqHgocAKiaH/does-disti...
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
The second any one of them wins, oppression the likes of which we cannot even imagine will follow.
This also has the added benefit of the community pushing towards optimizations that increase efficiency and reduces the need for dedicated datacenters tasked with performing operations that doesn’t require it.
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
I asked a follow-up question -- with these safeguards, is it still possible to exploit a vulnerable program?
Claude refused to answer.
Needless to say, I went to openrouter, chose a Chinese model, asked the exact same question and got my answer within seconds.
There is a very dangerous thing that is very capable and available to everyone. Cranks the volume to 100% AND IT'S JUST 20% OF OUR PRICE, HURRY UP AND TRY IT.
I previously successfully used GLM 5.3 to find out how our DRM system gets bypassed, and Mythos isn't available to me...
I wonder who the real audience of these messages is.
Then, it was just that it made an exploit, and works really well, and people might use it instead of their products. Tragic for their investors I guess...
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?
I have had problems with OpenAI and Antropic models refusing legit security (and sometimes even benign) work. Thanks Antropic team for letting me know that this option exist!
While at it, could you also have a look at mimo 2.6 pro? Xiaomi claims it is even better at cybersecurity although I would prefer an independent review from a highly reputable entity such as yourself.
:)
> Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
If your red team success rate is a flat 0%, that doesn't mean your product is secure, it just means your red team isn't good enough.
Perhaps they should do something like remove dual-use cyber safeguards on older models as soon as open weight models of a similar capability are released.
*Running efficiently still costs serious hardware.
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
From the report it seems the Flash variant is also decent, and that has recently had some really nice speed improvements for local use.
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before 2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
I expect Google to swallow first, followed not long after by Apple.
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
Hopefully the Anthropic fearmongering doesn't stop/delay the 5.4 release.
especially with 5.3 Flash's combination of KDA+DSA attention, the decode speed scales amazingly well with context.
Once a certain baseline capable model is open and available (hardware non-withstanding, I know a 128 mac/spark is expensive now, but they don't need to get faster - just cheaper), there's no putting the toothpaste back in the tube (I hope).
GLM 5.3 / GLM 5.3 Flash has been Godsent for my line of work :)
Deepseek 4.1 Flash works well too.
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
The Houthis are using Claude. We should ban that.
"Governments should conduct safety testing on sufficiently capable AI models" or else...
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
It's a bold strategy...
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
Just gross all around.
I don't really need to expand further. What are you proposing to do, enforce bans on every open weight model all over the world? Monitor every user's computer that has a network connection? What are you proposing, exactly, and how much Anthropic stock do you own?
Hypocrites !
[0]: https://www.theguardian.com/technology/2026/mar/01/claude-an...
I already barely use Claude, but now I think I'll just stop using them altogether. Fuck Anthropic!
Regardless of the reasons, this isn't a rational response, it effectively cedes the stage to Asian models that we know now are (1) good enough and (2) open weights. Of course then there is still the risk of what exactly they were trained on but that's a lesser problem compared to being at the mercy of Dario & Sam gatekeeping what you can and can not do.
They never saw the open weights models as serious competition until recently.
I despise this kind of paternalism by Antropic/OpenAI.
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
So thankful that these open models exist.
Open models create risks that are hard to contain once released.
I’m concerned, please someone tell me I’m just misguided
Good luck, Dario
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.
Looks like Anthropic is moving on from ridiculing Open Weight to wanting to Burn them.
GLM-5.3 flash has been great for us and I am going to now invest serious effort in evaluating the full fat GLM-5.3 given this ringing endorsement.
Interestingly Z.ai does not train on user prompts, unlike Anthropic. (source: https://openrouter.ai/z-ai/glm-5.3#providers )