{
  "id": 8529396,
  "title": "we have a year to fix security everywhere",
  "url": "https://urgent.news/2026/09/19/we-have-a-year-to-fix-security-everywhere",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-19T19:27:46.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://jyn.dev/a-year-to-fix-security/"
  },
  "original_language": "en",
  "account": "GLM 5.3-flash, developed by Z.ai Co., a Chinese AI lab, is now available for anyone to download and modify without the normal safeguards against malicious actions. This model, when hosted by Z.ai, includes required legal restrictions. However, once released publicly, organizations like DeAlignAI remove task refusals, allowing the model to perform various tasks, including potentially dangerous ones. GLM 5.3-flash can be run locally on consumer hardware, such as an NVIDIA GPU, achieving around 20 tokens per second. With the release of the M5 Mac Studio in September, the throughput is expected to increase to approximately 45 tokens per second, enabling the model to write code quickly. The model scores well on CyberGym (84.5%) and ExploitBench (54.4%) benchmarks, indicating its ability to identify and exploit vulnerabilities. Abliterated models, which lack task refusals, score slightly lower. Security experts believe that LLMs like GLM 5.3-flash will be essential for cybersecurity in the future, as humans are struggling to keep up with security challenges. While projects like Project Glasswing and Daybreak have made progress in fixing vulnerabilities, the critical part is deploying the fixes across systems, especially critical ones that may require physical access or careful planning to avoid downtime.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}