z.ai introduced GLM-5.3, an open-weight coding model positioned as a cybersecurity-capable successor to GLM-5.2, saying post-training with large-scale synthetic tasks improved both software development and security performance. The company said the model, developed with Chinese security researchers, helped uncover 2,436 previously unknown vulnerabilities across nearly 270 real-world projects, including more than 100 critical flaws affecting software such as the Linux kernel, WinRAR, Redis, and FFmpeg. z.ai also launched OpenVuln, a GitHub repository scanning service built around GLM-5.3, while delaying release of the model weights until further security evaluation and hardening are completed.
Independent benchmarking published by Semgrep found GLM-5.3 delivered comparatively strong cost efficiency on an IDOR vulnerability-detection test using real open-source codebases, roughly matching Claude Opus 4.8 at about one-seventh the cost. However, Semgrep said GLM-5.3 and several Grok 4.6 variants did not match the overall detection quality of current leaders Claude Opus 5 and GPT-5.6 Luna, and noted GLM-5.3 scored below its predecessor in that run, prompting a re-test to determine whether the gap reflects regression or normal benchmark variance. Across most models tested, precision was generally high but recall remained low, indicating the systems were usually accurate when they flagged issues but still missed many real vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Semgrep reported that GLM-5.3 scored below GLM-5.2 in this benchmark run and said it had not confirmed whether the gap reflected a real regression or normal benchmark variance. The company said it was re-running both models with multiple trials and planned to update its findings.
Semgrep evaluated GLM-5.3 and Grok 4.6 variants on its IDOR vulnerability-detection benchmark using real open-source codebases with established ground truth. It found neither matched the leading detection quality of Claude Opus 5 and GPT-5.6 Luna, though both offered comparatively strong cost efficiency.
z.ai introduced OpenVuln, a GLM-5.3-based service that appears to let GitHub maintainers submit repository URLs for vulnerability scanning and security review. The launch positioned GLM-5.3 as both a model release and a practical application for code security analysis.
z.ai said GLM-5.3 helped identify 2,436 new vulnerabilities across nearly 270 projects, including more than 100 critical flaws in software such as the Linux kernel, WinRAR, Redis, and FFmpeg. It also published a Vulnerability Ledger, while noting many findings had not yet been reported in detail to affected developers.
z.ai released GLM-5.3 as a new open-weight model and made it available to paying customers through its Coding Plan and ZCode harness. The company said public model weights would be published later, after additional security evaluation and hardening.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetheregister.com
Open sourceheise.de
Open sourcez.ai
Open sourcesemgrep.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.