We have a year to fix security everywhere
The GLM 5.3-flash model, released recently, has raised concerns about security vulnerabilities that can be exploited by anyone with access to the model and consumer hardware. This model, developed by Z.ai Co., a Chinese AI lab, lacks normal safeguards for refusing malicious actions, making it capable of doing anything. With the ability to run locally on stock consumer hardware, the model can generate outputs at a rate of around 45 tokens per second, enough to write code quickly and exploit vulnerabilities in real-time.
The model scores high on benchmarks related to finding and exploiting security vulnerabilities, indicating its potential to pose a significant threat. Despite efforts by organizations such as DeAlignAI to create abliterated models that remove task refusals, the GLM 5.3-flash model remains a significant concern for cybersecurity.
The deployment of fixes for these vulnerabilities across the industry remains a challenge, particularly for critical systems that require physical access or carefully planned rollouts. While some progress has been made by projects like Project Glasswing and Daybreak, there is still a pressing need to fix vulnerabilities across the industry before it's too late.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.