Chinese AI lab Z.ai — formerly Zhipu AI — released GLM-5.3 on August 14, calling it its most capable coding model to date and, by its own admission, a cybersecurity tool whose skills grew faster than expected.
Rather than training a new foundation model, Z.ai scaled post-training on the same 743-billion-parameter base used by GLM-5.2. The training environments increasingly resemble complete engineering jobs: agents receive codebases, documentation, compute clusters, storage systems and experimental results, then must diagnose problems, modify systems, run experiments and demonstrate measurable improvements while preserving correctness. Some tasks approximate several days of work for an experienced engineer. "Scaling post-training is all we did for GLM-5.3," the company wrote in its technical announcement.
The benchmark jumps are large: Terminal-Bench 3.0 rises from 4.6 to 28.3, DeepSWE v1.1 from 46.2 to 66.9, and AutomationBench from 26.2 to 48.2. On Z.ai's private Code Bench, GLM-5.3 reaches 34.5% at Max reasoning while consuming roughly 75,000 output tokens per task — versus 23.4% for GLM-5.2 on about 96,000 tokens, suggesting substantial efficiency gains as well.
The more unusual development is cybersecurity. "As we scaled post-training, cyber capability developed faster than we expected," Z.ai wrote. On CyberGym, GLM-5.3 scores 84.5%, and work with security teams in China has produced 2,436 vulnerability findings across 269 projects after expert review and deduplication — 1,097 rated critical or high severity. The model has reportedly already found a "potentially serious vulnerability" in Cursor, the AI coding startup recently acquired by SpaceX, according to Z.ai developer advocate Lou on X.
That sensitivity is why GLM-5.3 ships in stages. It is available now through Z.ai's GLM Coding Plan and ZCode environment, while API access and open weights follow in roughly two weeks "once safety evaluation and hardening are complete," the company says. Reuters reported Friday that Z.ai is also introducing controls around advanced capabilities, including a "trusted access" approach for sensitive functionality.
Developers face a breaking API change: unlike previous GLM models, thinking cannot be disabled. Applications sending thinking.type "disabled" must switch to "enabled" and specify a reasoning effort — making GLM-5.3 a real migration for some production systems.
The launch extends Z.ai's rapid push into long-running autonomous engineering, backed by roughly $4 billion raised in a Hong Kong share sale last month. It also demonstrates how far a frontier-scale base model can be pushed without another expensive pretraining cycle — and shows why deciding how such agents are distributed may become as important as deciding how they are trained.
Sources
- venturebeat.comGLM-5.3 is here with advanced cyber capabilities — and reportedly already found a 'serious vulnerability' in Cursor (VentureBeat)
- the-decoder.comZhipu AI releases GLM-5.3, claims it's the strongest open-weights coding model (The Decoder)
- axios.comChina's Z.ai holds GLM 5.3 release over hacking risks (Axios)
- interconnects.aiGLM-5.3: How Chinese labs keep stride with the frontier (Interconnects)




