# Z.ai’s GLM-5.3 Nears Anthropic’s Mythos 5 in Cyber-Defence Tests

> Source: <https://insideai.news/news/cybersecurity-ai/z-ais-glm-5-3-nears-anthropics-mythos-5-in-cyber-defence-tests/7816/>
> Published: 2026-08-14 11:10:05+00:00

**August 14, 2026**, (Inside AI) — Chinese startup **Z.ai** says its open-source **GLM-5.3** model nearly matched Anthropic's restricted **Mythos 5** in finding software vulnerabilities. The claim, made Friday, puts a Chinese challenger closer to a U.S. leader in cyber-defense testing.

Z.ai reported GLM-5.3 scored **84.5%** on **CyberGym**, a benchmark for reviewing code and confirming security flaws. That edged out the **83.8%** it reported for Mythos 5. The results have not been independently verified.

But the gap widened on turning flaws into working attacks. GLM-5.3 scored **54.4%** on **ExploitBench**, versus **78.0%** for Mythos 5. In a timed test, GLM-5.3 completed **105** attack-development tasks in two hours and **130** in six hours. Mythos 5 completed **181** and **247** tasks, respectively.

Anthropic restricts Mythos, a version of its **Claude Fable 5** with cybersecurity safeguards removed, to vetted organizations. The company worries such tools can lower barriers for attackers even as they help defenders.

Z.ai plans to release GLM-5.3 publicly in about two weeks after security assessments. Its most sensitive cybersecurity functions will require a “trusted access” program for verified users.

The company said it added layers of protection: screening risky requests, monitoring outputs, and training the model to reject malicious tasks. It said these separate harmful activity from legitimate uses like bug fixing or authorized security testing.

Critics argue safeguards weaken once a model is released for others to download, alter, or combine with outside tools. That tension frames a broader debate over open versus closed AI security models.

## Open-Source Push Targets Restricted Cyber Tools

Z.ai framed the launch as a direct challenge to closed-source Mythos. It argued advanced cyber-defense tools should serve open-source developers and smaller security teams, not just a few closed-model providers.

It announced an “**Open Source Shield**” initiative to audit selected open-source projects, provide model access for defensive work, and add code-auditing functions to its **ZCode** programming product.

Z.ai is not the first Chinese company to position a product against Mythos. Cybersecurity firm **360** said in June that its **Tulongfeng** vulnerability-discovery system achieved Mythos-equivalent capabilities by combining AI models with security data and automated tools. Those claims were also not independently verified.

GLM-5.3 differs. It is a general-purpose coding model that Z.ai says acquired cybersecurity skills through expanded post-training and reinforcement learning, rather than a purpose-built security system. It uses the same base model as **GLM-5.2** but trained in longer, more varied task environments.

## GLM-5.2 Momentum Fuels Global Interest

The launch builds on global interest in GLM-5.2, which gained attention among overseas developers for coding and agent capabilities. Users and analysts said it approached leading U.S. models at much lower cost.

That momentum may help Z.ai attract Western developers wary of U.S. export controls and high API prices. But independent verification of GLM-5.3's security claims remains a key hurdle.

Reporting by Eduardo Baptista. Editing by Mark Potter.
