Artificial intelligence

Z.ai Launches GLM-5.3 with Advanced Coding and Cybersecurity Capabilities

Chinese AI startup Z.ai has launched the GLM-5.3 model, which relies on scaling post-training for the GLM-5.2 model rather than building a new base model. The company says its cyber capabilities detected a potentially serious vulnerability in Cursor, while initial availability will be limited to the GLM Coding Plan and the ZCode environment until safety evaluations are completed.

2026-08-14
5 min read
13 views
فريق تحرير certi.news
Z.ai Launches GLM-5.3 with Advanced Coding and Cybersecurity Capabilities

Chinese AI startup Z.ai announced on August 14, 2026, the launch of the GLM-5.3 model, with major improvements in long-horizon coding tasks and a more significant leap in cybersecurity capabilities. According to Z.ai developer advocate Lou, the model’s cyber capabilities have already discovered a “potentially serious vulnerability” in Cursor, the AI coding company recently acquired by SpaceX. VentureBeat said it asked Cursor to confirm the incident and is awaiting a response.

GLM-5.3 is initially available only through the GLM Coding Plan and Z.ai’s ZCode environment. API access and open weights will come later, “after safety evaluation and hardening are complete,” according to the company, which plans to release the weights about two weeks after launch.

Major Improvements Through Post-Training

GLM-5.3 uses the same model base behind GLM-5.2, which is in the range of 743 billion parameters, and did not require a new pretraining cycle for its release. Instead, Z.ai expanded post-training across more environments and varied tasks, with additional reinforcement-learning compute. The company said in its technical announcement: “All we did in GLM-5.3 was scale post-training.”

The training environments simulate complete engineering tasks rather than isolated coding exercises; the agent receives codebases, documentation, compute clusters, storage systems, and experiment results, then is asked to diagnose problems, modify systems, run experiments, and prove measurable improvement while preserving the validity of the results. Some tasks are designed to simulate several days of work by an experienced engineer.

In evaluations announced by Z.ai, GLM-5.3’s score on Terminal-Bench 3.0 rose from 4.6 to 28.3, on DeepSWE v1.1 from 46.2 to 66.9, and on AutomationBench from 26.2 to 48.2. Its score on Agents' Last Exam CLI also improved from 23.8 to 28.5.

The model does not outperform all competitors in the tables published by the company; GPT-5.6 Sol scored 34.6 and Claude Fable 5 scored 33.7 on Terminal-Bench 3.0, compared with 28.3 for GLM-5.3. On DeepSWE v1.1, the model scored 66.9, compared with 72.7 for GPT-5.6 Sol and 69.7 for Fable 5. Z.ai also emphasizes token-use efficiency: GLM-5.3 achieved 34.5% on its proprietary Z.ai Code Bench test under the Max setting, using approximately 75,000 output tokens for the task, compared with 23.4% for GLM-5.2 using approximately 96,000. These results come from a company-specific test and are not independent measurements.

Cyber Capabilities Exceeded the Company’s Expectations

Z.ai introduced vulnerability-discovery environments into post-training, expecting improvements in finding software flaws. But it said the capabilities developed faster than expected, moving beyond identifying vulnerabilities to a greater degree toward building complete exploit chains.

GLM-5.3 achieved 84.5% on CyberGym, compared with 77.2% for GLM-5.2, narrowly exceeding the results Z.ai reported for both GPT-5.6 Sol at 83.6% and Mythos 5 at 83.8%. On ExploitBench, it scored 54.4%, more than twice GLM-5.2’s result of 24.4%, but remained behind GPT-5.6 Sol at 76.5% and Mythos 5 at 78%.

Z.ai said that work with security teams in China resulted, after review, screening, and deduplication, in 2,436 vulnerability discoveries across 269 projects. Its disclosure registry classifies 1,097 of these findings as high or critical severity, with 53 publicly disclosed and 2,383 remaining under embargo at launch. Reuters also reported that the company provides controls for some advanced capabilities, including a “trusted access” approach for sensitive functions.

Required Changes to Integration and Availability

Moving to GLM-5.3 requires modifications in some existing applications. The model supports low, high, and max reasoning-effort levels, with max as the default and recommended setting for coding. Thinking cannot be disabled as it could be in previous versions; therefore, applications that send thinking.type: “disabled” must change it to enabled and specify a reasoning-effort level, otherwise the request will fail.

The ZCode environment is available on macOS, Windows, and Linux, and supports long-horizon Goal tasks for planning, execution, testing, and verification, along with remote control of running tasks. Individual GLM Coding plans start, according to the listed promotional prices, at $12.60 per month for the Lite plan with 10,000 credits weekly, while Pro costs approximately $56 and Max approximately $117.60. Team Standard and Premium seats cost $88 and $188 per user per month, respectively. Z.ai did not announce public API pricing for GLM-5.3 in the provided launch materials.

News source
VentureBeat Startups & Funding
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news