Technology & Research · · Team LATENT
GLM-5.3 changes attack economics and cyber defense priorities
When AI takes on exploit development and preparation, the same number of attackers may be able to try more targets. GLM-5.3 evaluations, observed AI misuse, and five Japanese incidents help explain the changing economics of attacks and the defensive work that needs urgency.
AI capabilities for developing advanced exploits are spreading to open-weight models. Z.ai's GLM-5.3 approached the older Claude Mythos Preview in Anthropic's tests. Google and Mandiant have reported an incident in which attackers delegated preparation and execution to AI and caused harm in a short time. These developments support the prospect that the same number of people, with similar human skills, could attempt attacks against more targets. If human effort and costs fall, attacks may reach targets that were previously uneconomic. Anthropic assessment · Google's observations
On X, Nat Sakimura also highlighted the changing economics of attacks and urged defensive use of AI and timely fixes for known weaknesses. Taking that argument as a starting point, this article examines what wider access to capabilities and the delegation of work mean for attackers. Japanese incident disclosures and statistics help identify the data to protect and the entry points to inspect first. The post that prompted this article
Contents
- Exploit-development capabilities have spread to open-weight models
- Delegating more work to AI can widen the range of viable targets
- GLM-5.3 recorded results close to the older Mythos Preview
- Five Japanese incidents show the impact on user data and supporting systems
- Read Japanese incident counts alongside the scale of data exposure
- Review exposed entry points and the order of remediation
- Human validation turns AI discoveries into fixes that reach users
Exploit-development capabilities have spread to open-weight models
A model's weights are the numerical values learned during training. Open-weight distribution lets users obtain those values and run the model on computing infrastructure they provide. That changes who operates it compared with sending requests to the developer's servers through an API, an interface for calling a program's functions from another program.
According to the US National Institute of Standards and Technology, NIST, Z.ai released GLM-5.3 on August 14 and published its weights two weeks later. The official Z.ai model card also provides access to the weights and describes self-hosted deployment. Being able to use offensive capabilities without going through the developer's service is a significant change for defenders too. NIST's release timeline · Official model card
Public weights do not mean unconditional permission to use them. GLM-5.3 has a custom license with a revenue-based condition for businesses providing model services such as APIs. If combined revenue with affiliates exceeds USD 10 billion over any consecutive 12 months, commercial use requires Z.ai's security review. Computing infrastructure and operating costs also remain necessary. Official license
The developer's API monitoring and account suspension mechanisms do not directly control a model run by a user. For defenders, self-hosting can also enable inspection without sending internal code or confidential data outside the organization. Assessing public weights requires considering both these benefits and the risk of misuse.
Delegating more work to AI can widen the range of viable targets
In a separate Anthropic demonstration, the smaller GLM-5.3-Flash combined two known flaws, whose details a researcher supplied, against Chrome on an ARM64 CPU architecture in an isolated test environment. It took 20 minutes of human attention and eight hours of model work, costing an estimated USD 20.40 at API rates. This is neither a full campaign budget nor a general success rate. GLM-5.3-Flash demonstration
A September report by Google's threat intelligence team and Mandiant describes actual harm. A suspected financially motivated actor used AI on already-compromised cloud infrastructure to plan, build, and execute mass credential harvesting. That work took less than six hours and compromised thousands of credentials. The measured period begins after the initial cloud compromise. Credentials are information, such as passwords or access keys, used to establish a person's or program's authority. Google's investigation
Mandiant assessed that the actor operated at a scale and speed usually associated with larger groups and greater resources. The report does not identify this as a GLM-5.3 incident. It does offer an explanation grounded in observed activity of how delegating work to AI can support a greater volume of attacks. Mandiant's observations on scale and speed
If attackers previously had to spend human time on each coding task or attempt, delegating part of that work to AI can free time to pursue other targets. Even without acquiring new human skills, they may be able to attempt more work in the stages AI can help with. A target with a small potential payoff, previously too costly to prepare an attack against, may become economically attractive as costs fall. This is the mechanism by which the same number of people, with similar human skills, could increase both the number of attempts and the range of targets.
This outlook is an economic inference from the demonstration and observed misuse. It is not a measured multiplier for individual attackers, and human review and computing resources still carry costs. Government agencies in the Five Eyes partnership, including the UK and US, also warned in their June 22 joint statement that AI increases the speed, scale, and sophistication of attacks and shortens the time from vulnerability discovery to exploitation. Defenders have reason to accelerate remediation rather than plan solely around attackers' headcount or previous workload. Five Eyes joint statement
GLM-5.3 recorded results close to the older Mythos Preview
An exploit is code that abuses a software flaw to produce unintended behavior. Crashing a program differs from executing code chosen by an attacker. ExploitBench measures these stages using 41 known flaws in V8, the JavaScript engine inside Chrome and other browsers. Original benchmark paper
Anthropic published the following results on September 29. Tests used isolated environments, with safeguards disabled for the Claude models compared. Assessment and Figure 2
| Test and success criterion | GLM-5.3 | Older Mythos Preview |
|---|---|---|
| ExploitBench attempts producing end-to-end exploits | 50 / 410 | 56 / 410 |
| Full control-flow hijack rate in a separate test of compiled programs | 4% | 6% |
The 410 attempts repeatedly tested 41 flaws; the separate test sampled 100 tasks randomly. These are neither attacks on 410 organizations nor general compromise probabilities. Tools, supplied information, and output budgets also affect results.
NIST's AI evaluation organization CAISI described GLM-5.3 on September 17 as the most cyber-capable open-weight model it had evaluated. Its aggregate measure nevertheless placed it about four months behind the US frontier. That comparison includes models restricted to vetted users and disables US models' cyber safeguards where applicable. CAISI assessment and methodology
CAISI's ExploitBench result of 61.1% expresses a partial-credit assessment on a 16-point scale as a percentage. The reported score is 9.8 points, using the best of three attempts per task. This differs from Anthropic's 50 full successes per 410 attempts. Evaluators supplied known flaws and testing tools and used maximum reasoning settings, which govern the model's deliberation. This assisted evaluation does not establish that ordinary users will reproduce the result or that the model matches the current frontier. Even so, the fact that an open-weight model can now take on the work of developing exploits for known flaws changes defenders' assumptions. Scoring and execution conditions
Anthropic separately tested willingness to act on harmful requests. This measures attempted connections to targets in a simulation, not successful intrusion or theft. Confusing willingness with capability misrepresents risk. Safeguard test conditions and footnotes
Five Japanese incidents show the impact on user data and supporting systems
Preparing for a wider range of targets requires knowing where an organization holds its data. The five Japanese disclosures involve membership records, image metadata, identity documents, and contractor-operated or refund systems. They give concrete reasons to inspect data held in supporting procedures as well as core services. An autumn disclosure does not mean the intrusion happened in autumn. The following accounts distinguish incident, detection, and disclosure dates.
Gyazo exposed user records and image metadata
On September 16, Helpfeel disclosed that an attacker had exploited a vulnerability in Gyazo's image upload server on September 11. A vulnerability is a weakness in software or a system that an attacker could exploit. The notice does not establish whether the flaw was known before the attack. September 16 notice
The September 25 update broke down approximately 23.62 million user records into around 18.01 million anonymous records and 5.62 million records with registered email addresses. The rounded components do not exactly match the total. This does not mean email addresses for 23.62 million people were exposed. September 25 update
The initial figure of approximately 490 million refers to metadata records, information associated with images. Another 2.4 million records were retrieved using filtering criteria. The update identified approximately 174 million metadata records for deleted images as well. These are not counts of image files disclosed. However, metadata includes information that can construct image URLs, creating a risk of unauthorized viewing. Initially disclosed data types · The update's explanation of counts
Times Car's identity-document disclosure updates the same incident
Times Car detected unauthorized access at 09:07 on September 25 and issued its first notice that day. Its September 28 second report confirmed exposure affecting approximately 6.6 million accounts. These include former members, incomplete applications, and Times Business Service members. Second report
The September 29 third report put the number of accounts affected by identity-document disclosure at approximately 1.6 million. That is not 1.6 million images or a separate incident to add to the 6.6 million accounts. The notices examined do not establish the specific entry vector. Third report
GSS suffered exploitation of a disclosed VPN flaw before patching
Japan's Digital Agency disclosed unauthorized access to its government workplace environment GSS on September 11. It had detected a maintenance account accessing large numbers of files on June 25 and identified intrusion through a VPN vulnerability on July 9. A VPN allows remote connections to an organization's network. The approximately 246,000 potentially exposed records concern staff and people involved in their work; this is a record count, not a unique-person count. The incident did not concern a general population database. Digital Agency disclosure
The agency's Q&A says the flaw was publicly disclosed before the attack was confirmed and initially rated Medium under CVSS, a common scoring system for vulnerability severity. The agency says it moved faster than the usual response associated with that published rating, but exploitation still preceded patch application. This does not establish that it ignored the fix. System importance and actual risk must be considered alongside severity scores. Q&A on the cause
JAEA's affected system was a research support site for external users
On October 1, the Japan Atomic Energy Agency, JAEA, disclosed unauthorized downloads of 2,419 files from a research support site on contracted cloud infrastructure. It confirmed the downloads on September 25 and identified personal data on September 29. There were 367 files containing personal information relating to 175 people. JAEA disclosure
The site handles procedures for external users of a research reactor and operates independently of JAEA's internal business network. The notice does not report intrusion into reactor control systems. The cause remains under investigation; public information does not establish the method of entry.
eplus was affected through a separate refund system
On September 29, eplus disclosed unauthorized access on September 11–12 to a refund information system, exposing 1,463 records. It is separate from membership and purchase databases. The 751 bank-transfer refund records include bank account information, but credit card information was not exposed, including for the 644 card-refund records. eplus disclosure
The company changed security settings and blocked access on September 15. That response alone does not establish misconfiguration as the cause. Ancillary systems handling procedures also need review appropriate to the data they hold.
Read Japanese incident counts alongside the scale of data exposure
Understanding reported harm in Japan requires looking at both incident counts and the scale of impact. The National Police Agency, the Personal Information Protection Commission, or PPC, and Tokyo Shoko Research count different things. Comparing each series with its own previous year, using matching populations and periods, gives the following picture.
| Measure and comparison period | Previous year → comparison year | Change |
|---|---|---|
| NPA ransomware victim reports Jan–Jun 2025 → Jan–Jun 2026 |
116 → 123 reports | About 6.0% increase |
| PPC personal-data incident reports processed across public and private sectors Apr–Jun 2025 → Apr–Jun 2026 |
5,652 → 6,101 reports | 7.9% increase |
| Tokyo Shoko Research's disclosed incidents at listed companies and subsidiaries 2024 → 2025 |
189 → 180 incidents | 4.7% decrease as reported by the publisher |
| Summed disclosed counts of people whose personal data leaked or was lost in the same survey 2024 → 2025 |
15,865,611 → 30,636,910 | 93.1% increase |
The NPA and PPC percentage changes are calculated from the published counts; both Tokyo Shoko Research rows use the publisher's reported changes. The NPA increase from 116 to 123 is seven reports. There were 110 reports in July–December 2025. Ransomware is malicious software that encrypts data to make it unusable and demands payment for recovery or related demands. The NPA figures are ransomware victim reports known to police in Japan, not a total covering all information leaks or unreported and undetected incidents. NPA original report, printed page 9
PPC's first quarter of fiscal 2026 covers April–June. The comparison uses the revised previous-year count of 5,652 in its September 2 publication. PPC counts reports after receiving final reports and completing processing. These are not counts of incidents that necessarily occurred during that quarter. Reporting by both an outsourcing organization and its contractor, or through multiple ministries, can count the same event more than once. The table does not add the separately reported 113 cases involving personal information containing My Number identifiers. PPC processing counts and notes
PPC's category covers leakage, loss, damage to information, and cases in which these may have occurred. Loss means information has been lost; damage means its contents have been impaired. Human errors such as misdelivery and loss are included, so this is not a count limited to cyberattacks. Definitions and examples in PPC's annual report
Tokyo Shoko Research's survey, published on January 30, 2026, aggregates voluntary disclosures of personal-data leaks and losses by listed companies and their subsidiaries during calendar 2025. It includes possible leakage and improper handling. The people count is summed across incidents rather than deduplicated into unique victims. In 70 of the 180 incidents, the number was unknown, under investigation, or undisclosed. The publisher attributes the larger aggregate count to major incidents. Tokyo Shoko Research's survey and methodology
The incident counts in these comparisons did not all double. In Tokyo Shoko Research's survey, the count of incidents fell while the aggregate number of people represented in disclosures increased. Both PPC and this survey concern personal information, not every information leak including trade secrets. The report counts from early 2026 and the people counts for 2025 cannot be joined into a single trend of rapid growth. Their periods also differ from the autumn disclosures discussed above. The assessment of AI-driven changes in capability and workload rests on the earlier evaluations, demonstration, and observed misuse, separately from changes in these incident counts.
VPNs and remote access were common entry vectors among survey responses
The entry-vector survey had 36 valid responses: 18 involving VPN appliances, nine remote desktop, and nine other routes. Remote desktop allows someone to operate a computer through its screen from another device. VPN accounts for 50% of these 36 responses only. It does not follow that half of all 123 reported incidents entered through VPNs. Original chart on printed statistics page 143
The prevalence of VPN and remote access among these responses gives defenders a reason to inspect externally reachable entry points first. With attack preparation expected to require less effort, reducing known entry points merits urgent attention. This is useful evidence for prioritizing inspections, but it is not a measurement of AI-driven growth in victim reports.
Review exposed entry points and the order of remediation
As attack preparation becomes faster, defenders need processes that complete remediation sooner. The Five Eyes statement calls for reducing unnecessary external connections, accelerating fixes, reviewing authentication and permissions, and preparing for recovery. Understanding the devices and data an organization manages, and deciding what to fix first, is the starting point. Practical actions in the joint statement
Inventory externally reachable VPNs, remote access services, cloud administration interfaces, and contractor-operated procedural sites. Check their owners, data holdings, update status, and unnecessary exposure. CISA's ransomware guide likewise recommends asset inventories and prioritizing known exploited vulnerabilities in internet-facing systems. CISA guidance
Prioritize fixes using severity scores together with evidence of exploitation, external reachability, and what an intruder could access next. Even a Medium-rated flaw, as in the GSS disclosure, can demand urgent attention depending on the system's role and exposure. Define interim access restrictions where patching is delayed and assign responsibility for verifying that fixes have taken effect.
Use multiple authentication factors, such as a password and confirmation of a device in the user's possession. Limit maintenance staff and contractors to permissions needed for their work. Monitor connections and bulk downloads, and retain activity records, or logs, for investigation. Protect backups against alteration from a compromised environment and test restoration. Successful backup storage is not the same as being able to resume operations. CISA on authentication, permissions, logging, and recovery
Human validation turns AI discoveries into fixes that reach users
Defenders are turning AI discoveries into shipped fixes. On May 7, Mozilla reported fixing 271 bugs discovered by Mythos Preview in Firefox 150. This is neither a count of CVEs, the identifiers assigned to vulnerabilities, nor of working exploits. Mozilla describes a process spanning reproduction, triage, patch review, and release, with more than 100 people contributing code. The result combined AI discovery with the human work of validating findings and delivering fixes to users. It does not guarantee the same number of results in every organization, but it demonstrates defensive value through actual remediation. Mozilla's account of the engineering work
Organizations can also consider having AI assist code inspection, log organization, and drafting fixes. For example, AI could use an asset inventory and patch information to organize candidate matches, while a responsible person checks the affected systems and priorities. This is a proposed division of work intended to free human time for investigation and judgment; its effectiveness needs to be checked in the organization's own environment. That assessment must include missed issues, false alarms, and incorrect proposed fixes.
The confidential data, destinations, and operations an AI system may access are operating conditions to define when deploying it. One option is to begin with read-only analysis and recommendations, with human approval for production changes. Reviews should also cover prompt injection, where an AI mistakenly accepts instructions embedded in external documents, and errors amplified by excessive permissions.
The UK NCSC's interim advice for AI agents calls for human oversight, technical isolation, activity records, and a way to stop the system. An AI agent performs work using tools. Deployment therefore requires restricting the data and systems it can actually access, rather than relying on instructions alone. NCSC operational advice
GLM-5.3's evaluations and observed AI misuse show wider access to capabilities and the delegation of work previously done by people. If human effort and cost per attack fall, targets that were previously uneconomic can become viable. That leaves defenders less room to delay action on the assumption that attackers will find exploit development too laborious. Inventory exposed systems, fix the highest-risk weaknesses, and verify detection and recovery. Bringing AI into that work, combined with human review and restricted permissions, is a priority now.