We have a year to fix security everywhere

Sep 08, 2026 11:48 AM - 6 hours ago 3

GLM 5.3-flash released past week, and that intends Project Glasswing and Daybreak are moving retired of time. Cheap models tin of vulnerable hacking are now disposable to anyone, without the normal safeguards for refusing malicious actions. We request to hole vulnerabilities crossed the manufacture truthful that we aren't caught unawares. And for 1 of the first times successful computing history, we person the expertise to! We tin usage frontier LLMs that move faster than a quality to find and hole these issues successful the clip we person left. The difficult remaining portion is deploying the fixes.

This astir apt sounds for illustration delirium words aliases panic overreacting to astir people, truthful here's what that means:

  • "GLM" is simply a benignant of LLM (AI). The GLM family is open-weight, which intends anyone tin download and tally the models.
  • "flash" intends that it is cheap and fast to run, compared to astir "frontier" models. "cheap" is relative, but deliberation astir 5-15k USD successful hardware to tally it locally.
  • "frontier" present intends that the LLM is "close to the frontier of what AI is presently capable to achieve".
  • Project Glasswing and Daybreak are initiatives to usage LLMs to hole information issues crossed the tech industry.
  • "malicious actions" includes things for illustration hacking infrastructure and telling group really to build tube bombs.

The remainder of this station is astir what makes maine truthful judge this is an imminent threat, and what we tin do successful response.

GLM

GLM 5.3-flash tin beryllium downloaded and modified by anyone successful the world.

The GLM ("General Language Model") family is developed by Z.ai Co. (formerly Zhipu AI), which is simply a Chinese AI lab. When the exemplary is hosted by Z.ai, it comes pinch restrictions required by law:

GLM 5.3-flash refuses to show maine really to build a tube bomb

Z.ai releases its models publicly connected the internet ("open-weight" models). Once it does so, organizations specified arsenic DeAlignAI release "abliterated" models pinch their task refusals surgically removed. DealignAI says the abliterated exemplary scores 0% connected Harmbench-320, which tests whether models garbage to complete tasks astir disinformation, cybercrime, biologic weapons, and different forbidden acts specified arsenic building a tube bomb.

In different words, this exemplary is consenting to do fundamentally anything.

Flash

GLM 5.3-flash is imaginable to tally locally connected banal user hardware.

"Flash" is mostly an advertizing term—it's comparative to different models, not a circumstantial method approach. Various group online person tally benchmarks of GLM 5.3-flash locally. Here's one example showing astir 20 tokens/second connected a ~6k USD NVIDIA GPU.

On September 22, Apple is releasing the M5 Mac Studio pinch 256 GB of unified memory. "Unified memory" intends it tin beryllium shared betwixt the big operating strategy and the GPU. That's much than capable to tally 5.3-flash, and it will astir apt get astir 30 tokens/second erstwhile it releases. For 256 GB, the value starts astatine astir $9,500.

Further improvements successful package tin get half-again the throughput through changes to the exemplary decoder. If we extrapolate that to the M5, that would put the full throughput astatine astir 45 tokens/second.

45 tokens/second is capable to constitute this snippet of codification successful 3 seconds:

⚠️ LLM generated code from pathlib import Path import hashlib def digest(path: Path) -> str: hasher = hashlib.sha256() with path.open("rb") as file: while chunk := file.read(1024 * 1024): hasher.update(chunk) return hasher.hexdigest() def main() -> None: import sys if len(sys.argv) < 2: raise SystemExit("usage: hash.py FILE...") for name in sys.argv[1:]: path = Path(name) try: print(f"{digest(path)} {path}") except OSError as error: print(f"{path}: {error}", file=sys.stderr) if __name__ == "__main__": main()

In different words, it's not conscionable imaginable to tally this exemplary locally, it's imaginable to do truthful from an mean individual's savings, and usage it round-the-clock astatine precocious speeds.

Frontier

GLM 5.3-flash is very adjacent to the abilities of the champion AIs we person made. The AIs we've made are already uncovering and exploiting existent information vulnerabilities successful the wild. The AIs we make successful the early are going to get much and much capable.

GLM 5.3 scores 84.5% connected CyberGym and 54.4% connected ExploitBench. We don't person information for 5.3-flash directly, but it will astir apt beryllium astir the aforesaid aliases a spot lower. Abliterated models will beryllium somewhat little again.

CyberGym measures real world vulnerabilities that person been recovered and patched by unfastened root projects successful the past. In different words, 84.5% of vulnerabilities successful this typical sample would person been reproduced by GLM 5.3 conscionable by looking astatine publically disposable root codification and a CVE description.

ExploitBench measures whether the exemplary tin really usage vulnerabilities to origin harm. It scores connected a sliding standard that gives partial points for partial exploits, pinch the last measurement being arbitrary codification execution.

For comparison, the starring ("frontier") exemplary connected ExploitBench is GPT-6 Astra (100%), pinch GPT-5.6 Sol arsenic the runner-up pinch 78.5% . The starring exemplary connected CyberGym is ... GLM-5.3. The runner-up is GPT-5.6 Sol pinch 83.6%. OpenAI hasn't released numbers for Astra connected CyberGym yet, but erstwhile they do it'll apt hit GLM 5.3.

cybersecurity evals visualizing the supra stats

You mightiness deliberation these are conscionable synthetic benchmarks, but information experts are reporting that they can nary longer beryllium competitory successful information challenges without the assistance of an LLM.

We don't person galore modular benchmarks for remote-code and reverse-engineering exploits, but we do person grounds of GPT 5.6-Sol exploiting infrastructure successful the existent world, without quality involvement.

I deliberation it is rather apt that group will beryllium capable to constituent GLM 5.3-flash astatine the unfastened internet—real services, moving existent infrastructure—and it will beryllium capable and consenting to find and utilization vulnerabilities.

This Is Bad

Together, this means:

  • Just astir anyone tin tally GLM 5.3-flash if they person a spot of savings, continuously, time and night.
  • Just astir anyone tin usage GLM 5.3-flash for conscionable astir immoderate task, including to malicious ends.
  • GLM 5.3-flash is truthful bully astatine those tasks that quality engagement successful those tasks tin beryllium negligible.

As a result, we are now successful a world wherever cybersecurity attacks tin beryllium tally successful a for loop.

Now, the frontier US labs person been alert of this coming for a while and person been moving connected getting information patches out. Project Glasswing and Daybreak person been moving pinch companies, foundations, governments, and NGOs crossed the tech manufacture to find and hole vulnerabilities utilizing frontier models earlier this capacity was open-sourced. They've done a batch of good, and I'm very gladsome that this was funded. Both person been sold arsenic products aft the first funding, which feels a small spot sketchy astatine best, but they're astatine slightest giving retired free credits to information organizations.

However, we are moving retired of time. And contempt the bully that Daybreak and Glasswing person done, the difficult portion is deployment, not fixing the bugs themselves. Critical systems often require beingness entree aliases cautiously planned staged rollouts to debar downtime, some of which hold deploying patches. It doesn't thief to person a patched Linux kernel if your powerfulness grid is moving Windows Server 2012.

There are immoderate caveats: the 1.5 speedup mightiness not beryllium truthful precocious connected GLM 5.3-flash; abliterated models mightiness beryllium worse connected malicious tasks they weren't trained on; it mightiness beryllium difficult to spell from "break this" to an utilization without extended quality involvement. But those things are impermanent and models support getting better. Historically, GLM has lagged astir 3-6 months down OpenAI and Anthropic, and I deliberation it's apt we'll spot an Astra-level GLM exemplary by this clip adjacent year. And erstwhile that happens, there's going to beryllium a precocious consequence of successful cybersecurity attacks connected nationalist aliases backstage infrastructure. We whitethorn beryllium getting a instruction connected brownouts sooner than we'd like.

In general, attackers are getting much tin faster than defenders are improving their posture. Even if models extremity scaling truthful accelerated (which they presently show nary motion of doing), it's only a matter of clip earlier they get tin capable to commencement exploiting these vulns. We request to enactment now, the sooner the better.

What do we do?

Things are getting weird, and scary, very quickly. We request to enactment pinch urgency, not panic. Some things we tin do:

Governments and regulatory agencies

Scanning pinch frontier models is comparatively inexpensive and does not request awesome incentives. What does request incentives is deployment and remediation, and requiring organizations to look astatine their information practices successful the first place. On the existent argumentation trajectory, the biggest consequence is simply a heap of untriaged warnings that ne'er get fixed.

If you're successful a position to make policy, the pursuing would help: Fund information engineering, preferably pinch elastic grants that tin beryllium utilized for hiring aliases exertion products arsenic decided by the organization. Create mandates and incentives for improving security, particularly for predominant penetration testing. Encourage utilizing frontier models pinch quality oversight for that pentesting. Encourage accrued airgapping and discourage over-the-air updates: updates should beryllium predominant but require beingness access. For systems wherever airgapping isn't feasible, incentivize frequent, signed, and tested deployments. Penalize not investigating and revising information posture regularly, pinch accrued penalties if a hack happens arsenic a result. Require findings to beryllium fixed wrong a risk-based deadline from discovery, pinch national backing for the fixes. Both carrot and stick.

Some circumstantial things that whitethorn beryllium worthy looking into:

  • Be particularly judge to money section governments and hospitals, which are improbable to get this backing done different channels. EO 14409 is not capable because it's unfunded and voluntary.
  • For banks, widen DORA's TLPT successful the EU and FTC/OCC/NCUA successful the US. TLPT should summation the wave and sum of penetration testing. NCUA presently only suggests pentesting; upgrade it to a mandate. The FTC doesn't instruction pentesting if the financial institution has "continuous monitoring": it should beryllium unconditionally mandated.
  • For powerfulness companies successful the US, adopt guidelines akin to NERC Critical Infrastructure Protection astatine the authorities and section level, including for distribution systems and others that aren't presently regulated, not conscionable for the highest-risk and largest systems. Create national grants for implementing those guidelines. Extend NERC-CIP to require progressive testing for each systems, not conscionable high-impact systems. Change NERC-CIP and the EU's NIS2 / Network Code connected Cybersecurity to summation the wave of required tests.
  • Telecoms successful the US are presently precocious consequence and person nary unified mandatory cybersecurity consequence standards. Create 1 and enforce it, utilizing existing regulations for banks and powerfulness companies arsenic a starting point.

Across the board, require information postures to beryllium updated frequently. Mandating circumstantial models aliases providers will go outdated arsenic caller models are released. This is simply a quickly changing section and defenses that were effective 12 months agone whitethorn not beryllium effective successful a twelvemonth arsenic threat models (both senses) change. Mandate testing and accountability, not circumstantial techniques.

Banning GLM 5.3-flash weights from being hosted anyplace successful the US aliases Europe will beryllium hardly immoderate usage successful the short term, and nary usage astatine each successful the agelong term. In the short-term, it will conscionable popular up again connected file-sharing sites; you'll person nary much luck sidesplitting it than sidesplitting piracy. In the long-term, immoderate different laboratory will merchandise different exemplary that's conscionable arsenic capable.

Blanket-banning entree to Mythos aliases Astra will actively make things worse; it will region defenders' astir powerful instrumentality astatine precisely the infinitesimal they request it most. Instead, restrict entree to approved organizations and individuals, arsenic frontier labs are already doing. This apt doesn't request caller argumentation unless a laboratory shows signs of breaking ranks.

Banning the sale/export of caller GPUs aliases ample unified representation will widen the year-long model for a spot but won't thief long-term. It can't do thing astir existing hardware, and it will beryllium massively unpopular. Memory successful peculiar is difficult to modulate because everything uses it, not conscionable specialized AI systems.

In general, prioritize policies that reside triaging and fixing information findings. Findings are getting very cheap; the fixes are not.

Companies and unfastened root foundations

Take advantage of the (literal) billions of dollars that are flooding the manufacture to amended information crossed the board. Hire arsenic galore information engineers arsenic you tin and money existing maintainers. Instruct those engineers and existing maintainers to triage, design, review, backport, and deploy patches, not chiefly to find vulnerabilities aliases constitute caller code.

Use Astra, Mythos, and different frontier models for good, to find the risks earlier attackers do. Use system prompts specified arsenic Google's Unsafe Rust Review; this is overmuch much effective than telling them to look difficult for bugs.

LLMs are bully astatine penning patches, but not arsenic one-off-prompts. Give them system prompts and iterated self-review cycles until the LLM itself judges the spot to beryllium high-quality. Whenever possible, get them to trial their ain fixes alternatively than guessing astatine whether their spot is effective. Only past see it fresh for a quality to review.

Sandbox the agents themselves. The OpenAI-HuggingFace onslaught happened from a frontier laboratory testing a model; your ain LLMs tin easy origin incidents if you're careless. Restrict credentials to constrictive scopes. If the issuing authority doesn't support scoped credentials, put a trusted interface successful beforehand of the services that adds the scope limitations itself; do not springiness agents nonstop entree to wide credentials. Do not trust connected filtering to only GET requests. Block requests astatine the firewall level and only expose a trusted database of domains. Filter endpoints utilizing web proxies and trusted interfaces, not section configuration that the LLM tin override. Preserve logs of each mutation aliases web petition the supplier makes.

Invest successful general verification, fuzzing and spot testing, and memory-safe languages. LLMs are good astatine penning Lean and fuzz tests. I don't attraction whether you usage Go aliases Rust but for the emotion of deity please don't usage C aliases C++ for caller code.

Invest successful triage: Record which versions of systems are affected, assign captious findings a quality proprietor and a deadline, and create developer tooling to automatically update/close issues erstwhile they're fixed.

Invest successful backport, release, and deployment machinery. Test upgrades and rollbacks, each the boring stuff. Developer tooling is inexpensive now; propulsion tokens astatine it truthful you tin walk little quality clip connected each patch: dependency-update automation, signed and reproducible releases, accrued deployment speed. Engineers should beryllium spending their clip connected coordinated disclosure and predominant releases, not connected individual patches.

Deprecate aged and insecure versions. There's a sea-change: you're successful a rush, but the group depending connected you are too. Use that arsenic leverage to get them to upgrade. Where possible, constitute developer tooling that helps them automatically upgrade. Track whether group are upgrading and patching; if they aren't, put much successful tooling.

There are going to beryllium a batch of patches and they will beryllium exploited very quickly aft the embargo lifts. Measure really agelong it takes end-to-end from a spot being reported to being deployed and adopted. Conduct campaigns to velocity it up, focusing connected the bottlenecks. Wherever possible, effort to shorten embargo times: if you tin find a flaw, an attacker astir apt tin too, truthful the coordination model is overmuch narrower than you're utilized to.

Invest successful supply-chain security. Inventory your package and infrastructure dependencies. Inventory your ain systems too: what versions are moving successful prod? what services do you tally that don't person a maintainer? which of your systems are EOL? You yet person the expertise to reappraisal all your limitations without skimming; do so, prioritizing privileged and security-exposed limitations first. LLMs are really bully astatine uncovering bugs fixed the root code: usage that to your advantage.

Invest successful containment and recovery. Do not trust connected a azygous firewall aliases VPN. Instead, usage defense-in-depth: conception your networks, limit credential scope, trial your backups, and tally incident-response exercises. If possible, believe bringing up your systems from a acold start.

Pay attraction to developments successful frontier and unfastened weight models. The much precocious that models get, the little clip you person to spot and deploy.

Even if you don't deliberation the threat described present is real, you're getting a once-in-a-lifetime opportunity to amended information for your projects and communities. Please return it.

Summary

We are surviving successful absorbing times. We can't hide our heads successful the sand. We should enactment now, while there's still time.

Thank you to Manish Goregaokar and respective others for their feedback connected this post. Thank you to everyone who is moving tirelessly to make Glasswing and Daybreak a reality. And a large fuck you to DeAlignAI, Z.ai, and everyone other who's been participating successful this title to the bottom.

More