A blog post argues that the industry has roughly one year to patch security weak points before cheap AI makes them trivial to exploit. The post says a new publicly shared AI model, GLM 5.3-flash, can now find and use security weak points without much human help, and that anyone with a few thousand USD can run it at home.
What GLM 5.3-flash actually is
GLM is a family of AI models built by Z.ai Co. (formerly Zhipu AI), a Chinese AI group. The models are publicly shared, meaning anyone can download and modify them.
Once Z.ai Co. puts a model online, groups such as DeAlignAI put out altered copies with task refusals removed by surgery. According to the post, DeAlignAI’s altered copy of the model scores 0% on Harmbench-320, a test that checks whether a model refuses to help with things like false stories meant to mislead, computer crime, and building devices meant to cause harm. In plain terms, the post says, the model will attempt nearly anything asked of it.
Cheap enough to run at home
“Flash” is a marketing label for a smaller, faster version of a model, not a particular technical method, the post explains. Benchmarks cited in the post show the flash version running at around 20 tokens per second on a graphics card made by Nvidia, a company that builds the kind of computer hardware AI models need to run, costing roughly six thousand USD.
Apple is putting out the M5 Mac Studio on September 22 with 256 GB of unified memory, starting at around $9,500. The post guesses that machine could run the model at roughly 30 tokens per second, and possibly 45 tokens per second with software changes to how the model produces its text. At that rate, the post notes, the model can write a short piece of code in about 3 seconds.
How it compares to the best models available
GLM 5.3, the complete version, scores 84.5% on CyberGym and 54.4% on ExploitBench, according to the post. CyberGym tests whether a model can copy real weak points that have already been found and patched by open source projects, using only public source code and a CVE description. ExploitBench measures whether a model can turn a weak point into a working attack, giving partial credit up to full code execution with no limits placed on it.
For comparison, the post says GPT-6 Astra leads ExploitBench with 100%, with GPT-5.6 Sol second at 78.5%. On CyberGym, GLM 5.3 is the current leader, with GPT-5.6 Sol second at 83.6%. OpenAI has not yet put out Astra’s CyberGym score, though the post expects it to beat GLM 5.3 once it does.
No benchmark numbers exist yet for the flash version by itself. The post guesses it will land close to or a little below GLM 5.3’s scores, with the altered version scoring a bit lower still.
Why the post calls this dangerous
The post lays out why it considers this combination dangerous:
- Nearly anyone with modest savings can run GLM 5.3-flash day and night without stopping.
- Nearly anyone can point it at any task, ones meant to cause harm included.
- The model is skilled enough at these tasks that human help can be nearly nothing.
Put together, the post argues, this means attacks on computer systems can now run over and over on their own, without a person watching. For one of the first times in computing history, the post says, the side that protects networks has a matching means: strong AI models that can find and fix weak points faster than people can. The hard part left, the post says, is deploying the fixes.
The effort already in motion
Two efforts, Project Glasswing and Daybreak, have been working with companies, foundations, governments, and NGOs across the software industry to find and fix weak points using strong models before this kind of skill became available outside closed groups. The post credits these efforts with real progress but says the public arrival of GLM 5.3-flash greatly cuts down the time they were working within.
The post also points to a case already seen: GPT-5.6 Sol has, according to the post, already been used to break into infrastructure without a person directing it, though details on the scale or the system involved are not given. Here is the rough order of events laid out in the post:
| Date | Event |
|---|---|
| Last week | Z.ai Co. puts out GLM 5.3-flash as a publicly shared model |
| Following that | DeAlignAI puts out an altered version, scoring 0% on Harmbench-320 |
| September 22 | Apple puts out M5 Mac Studio with 256 GB unified memory, starting at $9,500 |
| Not dated in the post | GPT-5.6 Sol used to break into infrastructure without a person directing it |
| Coming year | Window described by the post for fixing weak points “everywhere” before attackers exploit them |
The post frames the next year as a contest between two uses of the same technology: one side fixing, the other attacking, both running on machines an ordinary person can buy.
Source: jyn.dev
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

