What this is

Anthropic's Frontier Red Team—the in-house safety unit that probes models for dangerous capabilities—released a number this week that should make the security community sit up. Zhipu AI, the Beijing-based foundation model company, had its GLM-5.3 tested on 100 "binary exploitation" tasks, where it achieved a 4% full control-flow hijack success rate. Anthropic's own next-generation Claude Mythos Preview scored 6%. The previous generation—Claude Opus 4.6 and GLM-5.2 included—scored 0% across the board.

The report's title is blunt: The Diffusion of GLM-5.3 and Advanced Cyber Capabilities. Binary exploitation, in plain terms, means "getting a program to step outside its intended behavior and do what an attacker wants." It is one of the hardest capabilities in offensive security. Control-flow hijack is the most severe subtype—an attacker seizes the program's next execution path entirely.

In other words, this test was not about who writes better code. It was about who actually has real low-level attack capability.

Industry view

Anthropic's own conclusion: "A meaningful threshold has been crossed." The subtext is unambiguous—advanced AI possessing low-level attack capability is no longer "theoretically possible." It is "happening now."

But we are hearing a more sobering counterpoint. Security researchers point out that 4%–6% sounds modest, but the real variable is not per-shot success rate; it is scale. Models can run 24/7, in parallel, tens of thousands of times at once. Work that once took a skilled hacker weeks can now be done in a few hours of API calls. Once the threshold exists, time and compute will close the rest of the gap for attackers.

There is also a restrained perspective worth weighing: dramatizing an "AI hacker arms race" risks obscuring the more pressing risk. The overwhelming share of what enterprises face today is models being used for large-scale phishing and automated social engineering—not low-level exploitation. The former is already deployed at scale; the latter remains too costly for most attackers.

Impact on regular people

For enterprise IT: The offense-defense balance is breaking down. Attacks that previously required elite security teams to reproduce can now be partially executed by calling an API. Security budgets and incident response playbooks need to formally list "AI-assisted attack" on the threat register.

For working professionals: This story is still relatively distant from most white-collar work. But if you work in IT, compliance, or risk for finance, healthcare, or government-adjacent sectors, it is worth flagging to your leadership whether AI attack tools have already entered your industry's actual threat model.

For consumers: In the short term, ordinary users will feel no direct impact. But if the AI offense-defense contest keeps heating up, the more likely next chapter is the underground commodification of exploit tooling—something security vendors and law enforcement will be wrestling with next.