{
  "id": 1430575,
  "title": "Zhipu va ouvrir les poids du meilleur chasseur de failles",
  "url": "https://urgent.news/2026/08/17/zhipu-va-ouvrir-les-poids-du-meilleur-chasseur-de-failles",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-17T06:00:06.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/thibault_monteiro/zhipu-va-ouvrir-les-poids-du-meilleur-chasseur-de-failles-16l5"
  },
  "original_language": "fr",
  "account": "Zhipu AI has unveiled GLM-5.3, an AI model trained on a 743 billion parameter foundation model and marketed as dedicated to cybersecurity and programming. The model achieved a score of 84.5 on CyberGym, outperforming Mythos 5 and GPT-5.6 Sol. Zhipu AI stated that they will release the model's weights in stages after security evaluations. On programming agent tasks, Zhipu claims significant progress over GLM-5.2, with fewer tokens produced while achieving better results. The Chinese company will first provide API access, followed by the release of weights in stages after security assessments. Unveiling a tool marketed as defensive is already a testament to its capabilities. The announcement gained traction due to a ranking: 84.5 points on CyberGym, surpassing Mythos 5 and GPT-5.6 Sol, for a model built on a foundation of 743 billion parameters. The benchmark assesses the ability to find vulnerabilities in real code. Repenting a flaw and writing its corresponding exploit rely on the same analysis work; the difference lies in the attack sequence, and that's where GLM-5.3 outperforms closed systems: approximately 54% success compared to 77% for the best closed models. The intent does not reside within the model's parameters; it lies in the person entering the prompt. Therefore, \"cyberdefense\" describes the intended use of the model, not a technical property of the delivered object. The most accurate remark came not from competitors but from responses under the announcement: a model excelling in this ranking is equally adept for offense, and nothing in a weight file prevents it from taking the wrong path. For an agent programming on a codebase, Zhipu claims a significant leap compared to GLM-5.2: better results with fewer tokens produced per task. The difference is quantified at around 50,000 tokens per task, whereas Opus 4.8 consumes 120,000 tokens, with slightly superior accuracy. This indicator matters to a technical team. An agent that loops on a codebase iterates three fewer times than GLM-5.2, changing the cost equation. The CyberGym score does not indicate the cost of your pipeline; it serves the publisher's communication and laboratory comparisons. The open-source release formula measures success: API access with open weights published in stages after rigorous security evaluations. Immediate and complete openness serves as a precautionary measure. However, it hints at a change in doctrine. Publishing a model tailored for cyberdefense prematurely admits that the same capability, in other hands, poses a problem the company can no longer arbitrate afterward. And the gesture is irreversible: once downloaded, a few hours of fine-tuning can flip the alignment safeguards, as retraining on a small dataset with accessible material renders the alignment moot. The security evaluation conducted beforehand only protects the period when the company retains access; it does not reduce the risk—instead, it programs the date of the risk. The audit of outdated dependencies, once a low-priority task due to lack of time, becomes the most profitable item on the security backlog. The structural advantage of defenders shrinks to one thing: they possess the source code and complete history before the attacker. Connecting a model of this caliber to one's own repository, before anyone else branches on your binary, is now a matter of ordinary hygiene. Running such a model does not require rare expertise or a large budget. The decision to act first determines the game. The final step—the release of weights—remains open. It commands everything else: the moment the file becomes downloadable, the publisher loses control, and the delay for teams that have not yet deployed such a model on their own code begins to run. My opinion: Zhipu likely has reason to publish, and they err in calling it defense. A model that excels at finding flaws will initially serve those who hunt them full-time, and those teams facing six-month delays in their corrections are not the ones who benefit. I await the emergence of derivative versions stripped of their safeguards in the weeks following the weight release.",
  "summary": "L'essentiel Zhipu AI a publié GLM-5.3, entraîné sur un modèle de base de 743 milliards de paramètres et présenté comme dédié à la cyberdéfense et à la programmation. Le modèle obtient 84,5 points sur CyberGym, au-dessus de Mythos 5 et de GPT-5.6 Sol. L'éditeur annonce un accès API et des poids ouverts (les paramètres du modèle, téléchargeables) publiés par étapes, après des évaluations de…",
  "key_points": [
    "Zhipu AI unveils GLM-5.3, a 743 billion parameter model for cybersecurity and programming.",
    "GLM-5.3 scores 84.5 on CyberGym, outperforming Mythos 5 and GPT-5.6 Sol.",
    "Zhipu will release model weights in stages after security evaluations."
  ],
  "editors_take": "Zhipu's release of its AI model's weights, though framed as for cybersecurity, likely benefits those who hunt flaws full-time, potentially shifting the structural advantage from defenders to attackers.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}