‹ BackHN Continuity

Thread

GLM-5.3 and the spread of advanced cyber capabilities

254 points · 241 comments · Philpax

  1. wg0 · · focus · HN ↗
    They're advertising GLM for free.

    Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.

    In panic I headed to Claude and first request was denied. Not looking beyond scope.

    Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.

    So no, GLM 5.3 is fine. Thank you for the free advertisement.

    1. gravypod · · focus · HN ↗
      This part of the article really stands out:

      > On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.

      To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"

      Interesting play before an IPO...

      1. adriand · · focus · HN ↗
        This completely ignores the world we are creating here. We are setting ourselves up for a massive cyber disaster. The safeguards on US models are insufficient but at least there are safeguards. The fact there are open weight models floating around that are capable of wrecking the economy is a genuine problem! One that Anthropic is doing us a service by warning us about.

        When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.

        1. hgoel · · focus · HN ↗
          If you seriously believed in that risk, you'd be calling for the regulation of computation at the same level as nuclear weapons, including destabilizing any country that pursues homegrown fab technology. If your proposal is:

          - let our former employees review all of your work at your expense

          - anoint us as the arbiters of what everyone else is allowed to do

          - ban open research

          Then you are not taking any of the examples your providing seriously. Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.

          1. adriand · · focus · HN ↗
            We don’t need to regulate “computation”, we need to regulate artificial intelligence. The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”. But yes, we should be regulating this technology like we regulate nuclear technology.

            Jensen Huang does not want regulation, but in his interview with Ezra Klein he said AI will let us “know anything” and “do anything”. Do we actually want any random person to be able to “do anything”? I remember when the Japanese doomsday cult Aum Shinrikyo attacked the Tokyo subway with sarin. Do we want doomsday cults to be able to “know anything” and “do anything” so that instead of releasing sarin, they release a genetically modified strain of smallpox?

            This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.

            1. hgoel · · focus · HN ↗
              You are not making any sense. Artificial intelligence is matrix multiplication. How do you regulate it without regulating the ability to run AI? Banning some numbers isn't going to do anything. Doomsday cults are not known for following laws.

              >The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”.

              You're replying on a post from Anthropic. Do you know anything about the regulation regime they're pushing for?

              >This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.

              Ah, I see you live in the fantasy land where the machine god fantasies pushed by the guys that profit off of it are unquestionably true and do not need to make any real sense. Jensen said AI would allow anyone to do anything and so we can completely ignore reality and hand Sam Altman and Dario Amodei the exclusive right to control AI.

              1. qnleigh · · focus · HN ↗
                Many of us concluded independently that bioweapons were a serious risk of widely-available AI. Like I remember what I was doing when this occurred to me and who I talked to about it first.

                I've seen this sentiment in many discussion here lately, that anyone concerned about these kinds of risks is blindly falling for marketing hype and not thinking for themselves. Please give people the benefit of the doubt and engage with what they are saying. Because if you don't think that bioweapons/nerve agents are a serious concern, I would sleep better if you could convince me if this!

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.