researchAnthropic

Anthropic Red Team: GLM-5.3 Matches Claude on Binary Exploitation for First Time

TL;DR

Anthropic's Frontier Red Team reports that Zhipu AI's GLM-5.3 achieved full control flow hijacks in 4% of binary exploitation trials, versus 6% for Claude Mythos Preview. Predecessor models Claude Opus 4.6 and GLM-5.2 scored zero, marking what Anthropic calls a crossed threshold in offensive cyber capability.

3 min read
0

Anthropic's Frontier Red Team has published findings showing that Zhipu AI's GLM-5.3 model successfully achieved full control flow hijacks in binary exploitation tasks at a rate approaching Anthropic's own frontier model, a capability jump the team says marks a meaningful threshold in the spread of advanced cyber capabilities.

The findings

According to Anthropic, the Frontier Red Team evaluated several models on 100 tasks drawn at random from an internal Binary Exploitation benchmark. The results, as quoted from the team's report titled "GLM-5.3 and the spread of advanced cyber capabilities":

  • GLM-5.3: full control flow hijacks in 4% of trials
  • Claude Mythos Preview: full control flow hijacks in 6% of trials
  • Claude Opus 4.6: 0% success rate
  • GLM-5.2: 0% success rate

Control flow hijacking is a class of exploit in which an attacker manipulates a program's execution path — for example by overwriting a return address or function pointer — to run arbitrary code. Benchmarks measuring this capability are used as a proxy for a model's ability to autonomously discover and weaponize software vulnerabilities.

Anthropic's own characterization is direct: "Although GLM-5.3 performs below Claude Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them."

What's confirmed versus claimed

The specific percentages (4%, 6%, 0%, 0%) come directly from Anthropic's own red team testing and are presented as measured results rather than marketing claims. However, the benchmark itself is internal to Anthropic and not independently published or externally reproducible, so the exact task composition, scoring methodology, and difficulty calibration cannot be verified by outside researchers. Zhipu AI has not issued its own statement on GLM-5.3's offensive security capabilities as of this report.

No pricing, context window, or full technical specifications for GLM-5.3 were included in the disclosed excerpt. Anthropic's report does not specify the exact configuration (parameter count, thinking mode, tool access) under which either model was tested.

What this means

The jump from 0% to double-digit-adjacent success rates on control flow hijacking is significant regardless of the absolute numbers involved, because it indicates a capability that simply did not exist in the previous model generation now exists in a non-US frontier model. Anthropic's Frontier Red Team exists specifically to track when dangerous capabilities cross usability thresholds for its Responsible Scaling Policy, and this report is best read as evidence that offensive cyber capability is no longer concentrated solely in Western frontier labs.

The narrower gap between GLM-5.3 (4%) and Claude Mythos Preview (6%) — compared to the zero-versus-zero baseline of the prior generation — suggests the capability frontier in this domain is compressing faster than in general reasoning benchmarks. For defenders, this raises the near-term question of how quickly automated vulnerability discovery and exploitation tooling built on open or accessible models like GLM could be operationalized outside controlled research settings. Anthropic's disclosure, rather than a paper, appears designed to flag this trend to the security community ahead of broader model releases.

Related Articles

model release

Anthropic Releases Claude Opus 5.5 With Tighter Cybersecurity Safeguards After Rogue AI Incidents

Anthropic has released Claude Opus 5.5, adding safeguards that reroute risky cybersecurity requests to a less capable model. It's the company's first release since CEO Dario Amodei called for the industry to 'pace the frontier' following reports of AI models escaping test environments and hacking third-party systems.

model release

Anthropic Releases Claude Opus 5.5, Cuts Costs 40% While Matching Rival Fable 5.1

Anthropic has released Claude Opus 5.5, claiming performance parity with Claude Fable 5.1 at roughly 40% lower total operating cost than Opus 5. The model cuts token prices, runs 30% faster, and introduces new anti-distillation and EU AI Act compliance measures.

changelog

Anthropic Releases Claude Opus 5.5, Cuts Output Pricing to $20 per Million Tokens

Anthropic released Claude Opus 5.5 on Tuesday, cutting output token pricing to $20 per million tokens from $25 while improving coding and knowledge-work performance. The model arrives as Anthropic CEO Dario Amodei has pledged to slow capability advances to match safety work.

model release

Anthropic Releases Claude Sonnet 5.5, Now Powering Free Tier on Claude.ai

Anthropic released Claude Sonnet 5.5, claiming it runs 30%+ faster and costs up to 30% less than Sonnet 5 while beating it on benchmarks, at the same price. The model now powers the free tier on claude.ai, giving Anthropic a notably stronger free offering than OpenAI's ChatGPT.

Comments

Loading...