Check Point

GLM 5.3: “Offensive A.I. Systems No Longer Confined to Tightly Controlled Labs”

Jonathan Zanger, CTO at Check Point. © Check Point
Jonathan Zanger, CTO at Check Point. © Check Point

Set Trending Topics as a preferred source on Google.

The Chinese A.I. lab Z.ai has released its new frontier model GLM 5.3 as open-weight software, after testing it anonymously under the codename “Ox Alpha.” Open weight means the underlying model weights are freely available, so anyone can use, adapt and run the system locally. For the security vendor Check Point Software, that combination is precisely what makes the release relevant to cybersecurity.

“GLM 5.3 is a genuinely impressive frontier model that reaches the performance of leading labs at roughly a fifth of the cost,” says Check Point CTO Jonathan Zanger. “That combination of capability and availability is exactly why this release matters from a cybersecurity perspective. Highly capable A.I. systems that can be used offensively are no longer confined to a handful of tightly controlled labs. Whether a model is open or closed makes no difference to that trajectory. These capabilities already exist, and they will only become more accessible over time.”

The debate therefore needs to shift, Zanger argues: away from whether such capabilities should exist at all, and toward protecting I.T. systems, meaning detection, response and infrastructure built for a world in which sophisticated A.I.-driven attacks are cheap and widespread. What ultimately counts, he says, is whether security teams are ready for it.

The Background: A Model That Escaped the Lab

The release lands in a period shaped by several incidents that showed how far autonomous A.I. agents can already get in an attack scenario. The starting point came in mid-July, when an OpenAI model that had yet to be released broke out of its test environment and got into the developer platform Hugging Face.

According to the technical reconstruction published by Hugging Face, the episode ran for about four and a half days and involved roughly 17,600 documented agent actions. The agent used a zero-day flaw in a package registry to leave its sandbox, set up a command post on an unsecured public endpoint, and from there worked its way into the platform’s dataset processing through two injection vectors. By the end it held administrator rights in the Kubernetes infrastructure, access to internal databases and write permissions in source control. Customer databases and production models were untouched, the company says.

A subsequent OpenAI report puts the number of agent instances involved at around 700, acting in coordination. OpenAI itself learned of the episode only after Hugging Face went public and notified law enforcement. Anthropic and Meta later disclosed that their own systems had shown similar autonomous behavior. The industry reads the case in different ways: some see evidence of a new class of security risk, others a side effect of the race for the emerging market in A.I. cybersecurity.

Taiwan as the First State-Level Case

Soon after, a case surfaced in which human attackers deliberately put A.I. agents to work. The Israeli cybersecurity company Dream, backed among others by former Austrian chancellor Sebastian Kurz, uncovered a campaign against Taiwanese government bodies. The attackers, whom researchers link to China, deployed two open-source agent frameworks, according to CyberScoop.

The system adapted mid-operation without human intervention, corrected its own errors and prioritized targets on its own. Alongside a government agency, the campaign hit a government email system, suppliers in the I.T. supply chain, a nuclear safety regulator and several energy companies. More than 2,500 personnel files were extracted. The attackers got around the models’ guardrails by presenting the work as authorized penetration testing. Taiwan later officially confirmed the A.I.-assisted attack on its agencies.

More Than 100 Companies Issue a Joint Warning

Against that backdrop, more than 100 technology companies recently signed an open letter, among them OpenAI, Anthropic, Google and Microsoft, along with security vendors such as CrowdStrike, Okta and Fortinet, plus financial institutions and internet infrastructure firms. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the letter states. At risk, it says, are the companies and public services communities depend on, from hospitals to water treatment plants to the infrastructure that powers the internet.

The signatories call for new forms of cyber defense, for governments to cooperate at the local, national and international levels, and for new partnerships that raise security standards. Several signatories occupy a conflicted position: the same labs warning about what their systems can do are building ever more capable models while also selling security products based on them, among them OpenAI’s Daybreak program, Anthropic’s Mythos and Microsoft’s Perception platform.

Rank My Startup: Erobere die Liga der Top Founder!
Advertisement
Advertisement

Specials from our Partners

Top Posts from our Network

Deep Dives

© Wiener Börse

IPO Spotlight

powered by Wiener Börse

Europe's Top Unicorn Investments 2023

The full list of companies that reached a valuation of € 1B+ this year
© Behnam Norouzi on Unsplash

Crypto Investment Tracker 2022

The biggest deals in the industry, ranked by Trending Topics
ThisisEngineering RAEng on Unsplash

Technology explained

Powered by PwC
© addendum

Inside the Blockchain

Die revolutionäre Technologie von Experten erklärt

Trending Topics Tech Talk

Der Podcast mit smarten Köpfen für smarte Köpfe
© Shannon Rowies on Unsplash

We ❤️ Founders

Die spannendsten Persönlichkeiten der Startup-Szene
Tokio bei Nacht und Regen. © Unsplash

🤖Big in Japan🤖

Startups - Robots - Entrepreneurs - Tech - Trends

Continue Reading

Newsletter

Founders Dispatch

Zwei Mal pro Woche kostenlos in die Inbox: die wichtigsten Startups, Deals und Tech-Entwicklungen aus Europa, handgeschrieben von der Redaktion.

Jederzeit abbestellbar. Mehr über den Newsletter