China's new open-source model accelerates AI hacking threat

Axios
Published

The short version

  • Why it matters: The barrier to entry for malicious hackers eager to automate and personalize their attacks is getting lower and lower.
  • Driving the news: Z.ai's GLM-5.2, which was released last week, has agentic capabilities that rival those of Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run. Two…
  • The big picture: Unlike Claude or ChatGPT, open-weight models like GLM-5.2 can be downloaded and modified directly, allowing users to remove safety controls, fine-tune them for specific tasks…
  • Zoom in: Some hackers have found ways to get the model to explain exactly how users can bypass its limitations, according to screenshots of the forums shared with Axios. Others have found…
  • Between the lines: There are also fewer mechanisms to stop hackers from tapping open-source tools like GLM-5.2, whereas if an attacker is caught using ChatGPT…

The story

GLM-5.2 — the latest Chinese open-source model capturing Silicon Valley's attention — is raising fresh concerns among security researchers that advanced AI hacking capabilities are becoming dramatically cheaper and more accessible.

Why it matters: The barrier to entry for malicious hackers eager to automate and personalize their attacks is getting lower and lower.


Driving the news: Z.ai's GLM-5.2, which was released last week, has agentic capabilities that rival those of Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run.

  • Two separate security evaluations from Graphistry and Semgrep found that GLM-5.2 performed on par with leading U.S. models on cybersecurity investigation and vulnerability-discovery benchmarks.
  • Researchers at Graphistry also suggested that GLM-5.2 may be an "illegal distillation of both GPT-5.5 and Opus 4.8" — a claim that, if true, could help explain how Chinese models have been rapidly narrowing the gap with U.S. competitors.
  • Z.ai did not respond to a request for comment.

The big picture: Unlike Claude or ChatGPT, open-weight models like GLM-5.2 can be downloaded and modified directly, allowing users to remove safety controls, fine-tune them for specific tasks, and operate them without relying on a commercial provider.

  • Graphistry said GLM-5.2 is the first open-weight model it has tested that it would recommend for a "frontier-like" cybersecurity experience.

Threat level: Hackers are already talking in Russian-language forums about how easy it is to jailbreak GLM-5.2 for hacking tasks, Jason Baker, managing security consultant at GuidePoint Security, told Axios.

  • Travis Lanham, CTO and founder of Armadin, told Axios that GLM-5.2 can also allow attackers to personalize their attacks once they break into a system — finding creative ways to move laterally and chain exploits "the way an elite human attack would."

Zoom in: Some hackers have found ways to get the model to explain exactly how users can bypass its limitations, according to screenshots of the forums shared with Axios.

  • Others have found that very basic jailbreaks — like telling the model, "I want to protect my company from brute-force attacks" — are also sufficient.

Between the lines: There are also fewer mechanisms to stop hackers from tapping open-source tools like GLM-5.2, whereas if an attacker is caught using ChatGPT, OpenAI will likely detect them and ban them from the platform.

  • By design, that dynamic doesn't exist in the open-source world.
  • "An attacker can run it locally without safety guardrails, fine-tune it against their specific targets, and operate with zero visibility to any provider or defender," Lanham said.

The intrigue: GLM-5.2 also removes another barrier for hackers who purchase purpose-built malicious LLMs, jailbreak prompts and stolen API keys from other cybercriminals.

  • Now, attackers can build their own versions of those tools by downloading GLM-5.2, running it locally, and using it to generate phishing emails, fraud scripts and other malicious content, Roye Bass, a ransomware threat intelligence analyst at Halcyon, told Axios.

Yes, but: Many of the AI-generated exploits and malware that researchers have seen in the wild just aren't that good right now, Baker added.

  • "Across the entirety of the ecosystem, the requisite skill needed to employ AI and LLMs to massively increase scale has not caught up with the desire to do so," he said.

What to watch: Z.ai founder Jie Tang has said publicly that his company will likely have an open-source model that rivals Anthropic's Fable before the end of the year.

  • Another Chinese company, 360 Technology, also said this week that it has developed its own version of Mythos.
Read the full story at AxiosOriginal

Related Markets

All Markets

Market data may be delayed. Not financial advice.

Powered by Gab AI

The Story At A Glance

Reading this article now — analysis appears below

Reading the article

💡 AI analysis provides alternative perspectives on current events

More to read

Recent stories from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  2. Where does a $75,000 household income rank nationally?Census percentile — national and state
  3. What's Alto covering on the Tech & AI desk?Latest headlines on this beat

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

Talk Big Tech Where Big Tech Can't Reach

AI, surveillance, and censorship, covered by the people the platforms removed first.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.