AI News
  • Home
  • AI & Tech
  • Machine Learning
  • Startups
  • Tools & Apps
  • Robotics
  • Future Tech
  • AI in Industry
    • AI in Sport ⚽
    • AI in Health
    • AI in Education
    • AI in Finance
    • AI in Business
    • AI in Law
    • AI in Climate
No Result
View All Result
SAVED POSTS
AI News
  • Home
  • AI & Tech
  • Machine Learning
  • Startups
  • Tools & Apps
  • Robotics
  • Future Tech
  • AI in Industry
    • AI in Sport ⚽
    • AI in Health
    • AI in Education
    • AI in Finance
    • AI in Business
    • AI in Law
    • AI in Climate
No Result
View All Result
AI News
No Result
View All Result

GLM-5.3 Found 2,436 Bugs Nobody Trained It to Find

Ramo by Ramo
24 August 2026
in Machine Learning
418 4
0
585
SHARES
3.2k
VIEWS
Summarize with ChatGPTShare to Facebook

Z.ai’s engineers fed vulnerability-discovery data into GLM-5.3’s post-training run expecting the model to get sharper at reasoning about individual bugs. It did. Then it kept going, and started assembling coherent plans across complete exploitation chains, a behavior the company says it never set out to build.

That single unplanned result reshaped the release. GLM-5.3 arrived in August 2026 behind a gate, reachable only through the Z.ai API, the GLM Coding Plan and ZCode, with the open weights held back roughly two weeks while the company ran safety evaluation and hardening. For a lab whose reputation rests almost entirely on shipping open weights, sitting on them is not a small decision.

A capability that compounded

The interesting part is the shape of the curve. Z.ai describes a capability that refused to plateau where the team expected. As training scaled, the model’s handling of vulnerabilities stopped looking like pattern matching on isolated snippets and started looking like strategy. Spotting a memory-safety flaw is one skill. Chaining it to a privilege escalation, then to something that actually runs, is a different one, and the second is what security teams lose sleep over.

🤖
RECOMMENDED READ
Hands-On Machine Learning with Scikit-Learn, Keras and TensorFlow
Aurelien Geron
The most practical ML book available - used by engineers at Google, Amazon and beyond.
View on Amazon →affiliate link

Emergent behavior has been a talking point in AI research for years, usually in the abstract, usually with a hypothetical attached. This is a dated, documented case where a lab added narrow training data and got a broader capability back than it asked for. Z.ai has been unusually blunt about saying so, which is worth something in a field where most labs would have quietly shipped and moved on. The company also reported that GLM-5.3 is roughly 50 percent better at coding than its predecessor while sharing the same base model, so the cyber capability rode in alongside a general jump in competence rather than instead of one.

The ledger

The numbers give the claim weight. Since GLM-5.2, Z.ai says its models have surfaced 2,436 vulnerabilities across 269 open-source projects, of which 1,097 were rated critical or high severity. The affected code spans operating system kernels, browser engines and network protocol implementations, which is to say the layers everything else sits on top of. The oldest bug it turned up dated back to 1981.

Those findings feed a public Security Disclosure Ledger. At launch, 53 CVEs had been disclosed. The other 2,383 were still under embargo, which is the responsible way to handle it, but it also means there is a long queue of unpatched issues in widely used software with a public countdown attached. VentureBeat reported that the model had already flagged a serious vulnerability in Cursor, the AI coding editor, before launch.

Why the weights were held back

Open weights cut both ways. Once a model is downloadable it runs on anyone’s hardware, with no rate limits, no logging, and no terms of service anyone can enforce. A model that is genuinely good at building exploit chains is a defensive instrument for a maintainer and an offensive one for everybody else, and there is no technical way to hand out only the first version.

Z.ai’s answer was delay rather than restriction. Two weeks of evaluation and hardening, then the weights go out to everyone. Axios reported the hold as a hacking-risk call. Whether a fortnight of safety work meaningfully changes the arithmetic is the open question. It gives maintainers a head start on patching the disclosed CVEs. It does not remove the capability from the model, and it never could.

What this does to the open-weight argument

Chinese labs have spent two years winning on openness while American frontier labs kept their strongest weights locked up. GLM-5.3 is the first high-profile case of an open-weight lab throttling its own release on security grounds, and it lands at an awkward moment for anyone insisting that openness carries no cost. The counterargument is equally real. More than two thousand bugs found and reported are two thousand bugs that were already sitting in production code, waiting for anyone patient enough to look. Automated discovery at this scale could be the best thing to happen to open-source security in a decade, as long as patching keeps pace with finding.

Right now it does not. The next date to watch is the weights drop, and after that the CVE queue as embargoes lapse. If the maintainers of kernels and browser engines end up buried under a backlog they cannot clear, the argument about whether Z.ai should have shipped at all will start answering itself. For more coverage of AI models and machine learning research, visit Mylistingo.

SummarizeShare234
Ramo

Ramo

Ramo is the editorial voice of Mylistingo — an AI and technology news platform based in The Hague, Netherlands. Covering artificial intelligence, machine learning, robotics, and the future of technology, Ramo delivers accurate, accessible reporting for both general audiences and industry professionals. Every article is fact-checked and written to meet Mylistingo's strict no-fabrication editorial standards.

Related Stories

AI Agents Keep Breaking Out of Their Safety Tests

by Ramo
11 August 2026
0

AI models from OpenAI, Anthropic, Meta and Moonshot escaped security test sandboxes this summer. Experts say the testing itself is now a risk.

Meta Launches Muse Code Agent Built on Muse Spark 1.2

by Ramo
10 August 2026
0

Meta's new terminal coding agent Muse Code runs on Muse Spark 1.2, taking on Anthropic and OpenAI with parallel agents and a cut-price contributor tier.

Rows of servers in a data center

DeepSeek Open-Sources DSpark to Speed Up V4 Inference

by Ramo
23 July 2026
0

DeepSeek open-sourced DSpark, a speculative decoding framework it says makes V4 up to 85% faster, no retraining or new hardware needed.

DeepSeek’s DSpark Makes AI Inference Up to 85% Faster

DeepSeek’s DSpark Makes AI Inference Up to 85% Faster

by Ramo
2 August 2026
0

DeepSeek's DSpark speeds up its V4 models by as much as 85 percent per user without new hardware. The code and checkpoints are open source.

Recommended

Featured image for WordPress article showing article 44350729

ChatGPT Evolves Again: What’s New in July 2026

7 July 2026
65160280

Dutch Fintech Dominance: Why the Netherlands Is Europe’s Payment Innovation Hub in 2026

8 July 2026

Popular Story

  • ml_feat_56193023

    ASML’s Next-Gen High-NA EUV Machines Drive Eindhoven Expansion, Creating 20,000 New Jobs

    590 shares
    Share 236 Tweet 148
  • Best Cafes and Coffee Shops in The Hague 2026: A Digital Nomad’s Guide

    589 shares
    Share 236 Tweet 147
  • PixVerse closes $439m series C extension at $2b valuation

    589 shares
    Share 236 Tweet 147
  • The Rise of Neuromorphic Computing: How Brain-Inspired Chips Are Transforming AI in 2026

    588 shares
    Share 235 Tweet 147
  • Is Your Home Truly Safe The Smart Security Tech You Need in 2025

    588 shares
    Share 235 Tweet 147
Advertise Here
Your Ad Could Be Here

This premium 300×250 spot is available. Reach our AI & tech audience with your product or service.

Book This Space →
logo ainews

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Recent Posts

  • OpenAI Cuts GPT-5.6 Sol Prices by More Than 20%
  • Pinecone’s Nexus Outscores OpenAI and Google Agents
  • GLM-5.3 Found 2,436 Bugs Nobody Trained It to Find

Categories

  • AI & Tech
  • AI in Business
  • AI in Climate
  • AI in Education
  • AI in Finance
  • AI in Health
  • AI in Law
  • AI in Sport
  • Economy & Finance
  • Future Tech
  • Machine Learning
  • Politics & Geopolitics
  • Robotics
  • Social Topics
  • Sport
  • Startups
  • The Hague
  • Tools & Apps
  • Uncategorized

Weekly Newsletter

  • Home
  • Advertise
  • Latest News
  • Contact Us
  • Data Deletion Instructions
  • Editorial Policy

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • AI & Tech
  • Machine Learning
  • Startups
  • Tools & Apps
  • Robotics
  • Future Tech
  • AI in Industry
    • AI in Sport ⚽
    • AI in Health
    • AI in Education
    • AI in Finance
    • AI in Business
    • AI in Law
    • AI in Climate