The bar for open-weight AI just got a whole lot higher. A Chinese AI company called Z.ai, which many of you might know as Zhipu AI, just dropped GLM-5.3. This massive 743-billion-parameter model has been officially launched, pushing the boundaries of coding and cybersecurity capabilities.
This launch is truly important for open-source AI. It shows that just scaling things up after training, without even messing with the architecture, can seriously boost how well a model works in all sorts of different areas.

Emergent cyber capabilities surprise developers
As Z.ai scaled post-training with more environments and reinforcement learning tasks, the model’s cybersecurity capabilities “developed faster than we expected.”
GLM-5.3 scored 84.5 percent on CyberGym, a benchmark testing vulnerability discovery through source code analysis, narrowly beating Anthropic’s restricted Mythos 5 at 83.8 percent.
The model’s gains were most pronounced on complex exploitation tasks: ExploitBench scores more than doubled from GLM-5.2’s 24.4 percent to 54.4 percent.
In real-world testing, GLM-5.3 identified 2,436 vulnerabilities across 269 open-source projects, including 1,097 critical or high-severity issues, some dating back 45 years.
Performance across key benchmarks
The AI model‘s coding capabilities saw important improvements across the board. On Terminal-Bench 3.0, scores jumped from 4.6 to 28.3, while DeepSWE v1.1 rose from 46.2 to 66.9.
GLM-5.3 also showed it’s way better with tokens on Z.ai’s internal Code Bench, beating out Claude Opus 4.8 at high effort levels while using fewer tokens.
Responsible release strategy
Z.ai is taking a staged approach to release. GLM-5.3 is currently available to paying customers via Application Programming Interface and the ZCode harness.
The company will release complete model weights two weeks after completing safety evaluations, with “trusted access” for sensitive cybersecurity functions.








