TLDRocket
Sign in

Quoting Anthropic Frontier Red Team

Simon Willison’s Weblog Simon Willison

Anthropic’s red team says GLM-5.3 got full control-flow hijacks in 4% of tests. That’s less than Claude Mythos Preview, but older models hit zero.

Based on reporting by Simon Willison’s Weblog, Simon Willison — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Anthropic’s Frontier Red Team has put a sharper edge on the cyber chatter around GLM-5.3. In a quote collected by Simon Willison, the team says it tested several models on 100 tasks drawn at random from an internal Binary Exploitation benchmark.

The headline result is blunt: GLM-5.3 developed full control-flow hijacks in 4% of the trials. Claude Mythos Preview did it in 6% of them. That puts GLM-5.3 behind Anthropic’s own preview model, but not by much.

The more important point is the one tucked into the same line: a meaningful threshold has been crossed. Earlier models mentioned in the quote, Claude Opus 4.6 and GLM-5.2, did not succeed on any of the tasks.

So this isn’t just a scorecard. It’s a sign that capabilities in advanced cyber work are moving from theoretical concern to measurable behavior, even if the rates are still low. Once a model can start producing full control-flow hijacks at all, the conversation changes fast.

The quote was posted by Simon Willison on 29 September 2026 at 10:20 pm, and it comes with the usual reminder that benchmark snippets can be revealing in very specific ways. This one is.

My take — AI-written commentary, not fact-checked reporting

The industry loves to talk about frontier models like they’re all the same flavor of smart. They’re not, and cyber work is where the differences get embarrassing fast. If a model can cross from zero into even a few percent on exploit tasks, the safe-to-sell rhetoric deserves a long walk outside.

Read more about this at: Simon Willison’s Weblog

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.