// HACKER NEWS — CYBERSECURITY
We have a year to fix security everywhere
2026-09-04
• llms
• security
GLM 5.3-flash released last week, and that means Project Glasswing and Daybreak are running out of time.
Cheap models capable of dangerous hacking are now available to anyone, without the normal safeguards for refusing malicious actions.
We need to fix vulnerabilities across the industry so that we aren't caught unawares.
And for one of the first times in computing history, we have the ability to!
We can use frontier LLMs that move faster than a human to find and fix these issues in the time we have left.
The hard remaining part is deploying the fixes.
This probably sounds like nonsense words or hysterical overreacting to most people, so here's what that means:
The rest of this post is about what makes me so sure this is an imminent threat, and what we can do in response.
GLM 5.3-flash can be downloaded and modified by anyone in the world.
The GLM ("General Language Model") family is developed by Z.ai Co. (formerly Zhipu AI), which is a Chinese AI lab.
When the model is hosted by Z.ai, it comes with restrictions required by law:
Z.ai releases its models publicly on the internet ("open-weight" models).
Once it does so, organizations such as DeAlignAI
release "abliterated" models with their task refusals surgically removed.
DealignAI says the abliterated model scores 0% on Harmbench-320,
which tests whether models refuse to complete tasks about disinformation, cybercrime, biological weapons, and other illegal acts such as building a pipe bomb.
In other words, this model is willing to do basically anything.
GLM 5.3-flash is possible to run locally on stock consumer hardware.
"Flash" is mostly an advertising term—it's relative to other models, not a specific technical approach.
Various people online have run benchmarks of GLM 5.3-flash locally.
Here's one example showing around 20 tokens/second on a ~6k USD NVIDIA GPU.