{"id":88998,"date":"2026-06-29T02:27:16","date_gmt":"2026-06-29T02:27:16","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/88998\/"},"modified":"2026-06-29T02:27:16","modified_gmt":"2026-06-29T02:27:16","slug":"buckle-up-the-bad-guys-now-have-a-model-as-powerful-as-mythos","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/88998\/","title":{"rendered":"Buckle Up: The Bad Guys Now Have A Model As Powerful As Mythos"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/06\/1782700036_715_0x0.jpg\" alt=\"In this photo illustration, a Zhipu AI logo is seen\" data-height=\"3333\" data-width=\"5000\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>In this photo illustration, a Zhipu AI logo is seen displayed on a smartphone with the Chinese flag in the background. (Photo Illustration by Avishek Das\/SOPA Images\/LightRocket via Getty Images)<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>China now has an open-weight model that does the kind of long-horizon, repository-scale coding work U.S. officials spent the spring treating as a national-security problem when it came from American labs. <\/p>\n<p><a href=\"https:\/\/venturebeat.com\/technology\/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/venturebeat.com\/technology\/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost\" aria-label=\"GLM-5.2\">GLM-5.2<\/a>, released by Z.ai last week under an MIT license, is downloadable by anyone, runs on private hardware, and leaves no provider-side record of how it&#8217;s used. That last detail is the governance problem. The control regime Washington built around frontier cyber-AI assumes a vendor sits between the model and the user. Open weights remove the vendor.<\/p>\n<p>Mythos: the warning shot<\/p>\n<p>Anthropic introduced Mythos as a model so good at finding software flaws that the company kept the most capable version, Mythos 5, inside a small partner program called Project Glasswing. It released to the public a safer sibling, Fable 5. <\/p>\n<p>Within days of Fable\u2019s June 9 launch, however, the Trump administration forced Anthropic to withdraw it after <a href=\"https:\/\/www.cnn.com\/2026\/06\/13\/business\/anthropic-mythos-model-national-security\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cnn.com\/2026\/06\/13\/business\/anthropic-mythos-model-national-security\" aria-label=\"another company demonstrated it could jailbreak the model\">another company demonstrated it could jailbreak the model<\/a>. The Wall Street Journal reported the push came from Amazon CEO Andy Jassy, who told Treasury Secretary Scott Bessent that Amazon researchers had used Fable prompts to pull information useful for cyberattacks. On June 12, the administration invoked export-control authority to bar foreign-national access to both models (including Anthropic\u2019s own non-citizen staff), which forced the company to <a href=\"https:\/\/fortune.com\/2026\/06\/13\/anthropic-disables-fable-mythos-export-controls-national-security-threat\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/fortune.com\/2026\/06\/13\/anthropic-disables-fable-mythos-export-controls-national-security-threat\/\" aria-label=\"disable them worldwide\">disable them worldwide<\/a>.<\/p>\n<p>On June 26, Commerce Secretary Howard Lutnick told the company that Mythos 5 could return for <a href=\"https:\/\/www.nbcnews.com\/tech\/tech-news\/us-government-gives-anthropic-green-light-limited-re-release-mythos-5-rcna352018\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.nbcnews.com\/tech\/tech-news\/us-government-gives-anthropic-green-light-limited-re-release-mythos-5-rcna352018\" aria-label=\"roughly 100 vetted U.S. organizations\">roughly 100 vetted U.S. organizations<\/a> \u2014 government agencies, banks, infrastructure providers \u2014 on the grounds that adequate safeguards were finally in place. Fable 5, the consumer model, <a href=\"https:\/\/cybernews.com\/ai-news\/anthropic-mythos-us-gov-approval\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/cybernews.com\/ai-news\/anthropic-mythos-us-gov-approval\/\" aria-label=\"stayed restricted\">stayed restricted<\/a>. High-end AI are now treated as dual-use technology, not productivity software \u2013 at least in the U.S.<\/p>\n<p>GPT-5.6 and the same logic<\/p>\n<p>OpenAI\u2019s <a href=\"https:\/\/www.axios.com\/2026\/06\/26\/openai-gpt-sol-terra-luna-trump\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.axios.com\/2026\/06\/26\/openai-gpt-sol-terra-luna-trump\" aria-label=\"GPT-5.6\">GPT-5.6<\/a> arrived under the same constraint. The company released only a limited preview to about 20 companies whose participation the government approved.<\/p>\n<p>What GLM-5.2 changes<\/p>\n<p>GLM-5.2 inverts that arrangement. Z.ai, the Beijing lab formerly known as Zhipu AI, shipped the model weights under an MIT license: a 744-billion-parameter mixture-of-experts model with a context window reaching a million tokens, enough to take in an entire code repository. On <a href=\"https:\/\/artificialanalysis.ai\/articles\/glm-5-2-is-the-new-leading-open-weights-model-on-the-artificial-analysis-intelligence-index\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/artificialanalysis.ai\/articles\/glm-5-2-is-the-new-leading-open-weights-model-on-the-artificial-analysis-intelligence-index\" aria-label=\"agentic coding benchmarks\">agentic coding benchmarks<\/a> it beats GPT-5.5 outright and lands within a few points of Claude Opus 4.8, at roughly a sixth of the API cost.<\/p>\n<p>The benchmarks that matter for this argument are the security ones. Two independent evaluations found GLM-5.2 performing on par with leading U.S. models on vulnerability discovery. <a href=\"https:\/\/semgrep.dev\/blog\/2026\/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/semgrep.dev\/blog\/2026\/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks\/\" aria-label=\"Semgrep\">Semgrep<\/a> had it beat Claude on an IDOR-detection task at about 17 cents per bug found; <a href=\"https:\/\/www.graphistry.com\/blog\/glm-5-2-cybersecurity-open-model\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.graphistry.com\/blog\/glm-5-2-cybersecurity-open-model\" aria-label=\"Graphistry\">Graphistry<\/a> called it the first open-weight model it would recommend for a frontier-grade cybersecurity experience. Within days, <a href=\"https:\/\/www.axios.com\/2026\/06\/25\/china-glm-52-open-source-hackers\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.axios.com\/2026\/06\/25\/china-glm-52-open-source-hackers\" aria-label=\"Axios reported\">Axios reported<\/a> hackers trading jailbreaks on Russian-language forums and one researcher describing the model chaining exploits &#8220;the way an elite human attack would.&#8221; None of this needs Z.ai&#8217;s cooperation, or even its awareness. Once the weights are local, the company can&#8217;t shape or see what the model does.<\/p>\n<p>Three models, one variable<\/p>\n<p>Line the three up and the variable isn\u2019t capability, it&#8217;s containment. Mythos is the most dangerous on paper, optimized for vulnerability discovery and demonstrably able to surface flaws in bulk, which is precisely why it sits behind suspensions, export limits, and a vetted-partner list. GPT-5.6 is strong across coding and security tasks but reaches users only through governed endpoints and an approved-customer roster. GLM-5.2 is the one with no wrapper. The first two are high-capability tools inside an enforcement layer; the third is the tool by itself, on whatever hardware someone points it at.<\/p>\n<p>How fast does this matter?<\/p>\n<p>The open question is speed, not direction. Anthropic CEO Dario Amodei <a href=\"https:\/\/www.cnbc.com\/2026\/05\/29\/mythos-ai-models-eu-talks-us.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cnbc.com\/2026\/05\/29\/mythos-ai-models-eu-talks-us.html\" aria-label=\"warned in May\">warned in May<\/a> that Mythos had already turned up tens of thousands of software vulnerabilities, and that defenders had perhaps six to twelve months to patch them before comparable capability spread more widely. GLM-5.2 is what &#8220;spread&#8221; looks like. A competent operator can wire it into existing scanners, fuzzers, and CI pipelines to accelerate both defense and offense, and because the runs are local, the cloud logs defenders rely on to catch abuse simply aren&#8217;t generated.<\/p>\n<p>That\u2019s not a forecast of autonomous exploit campaigns by next quarter, but it does move AI-accelerated attack-surface analysis from horizon risk to current operational fact.<\/p>\n<p>For boardrooms<\/p>\n<p>The takeaway for boards and CISOs isn\u2019t that one Chinese release upended the field overnight. It\u2019s that the working assumption that the most capable cyber-AI would stay behind gated APIs and government deals no longer holds. Mythos showed that governments will pull a model they consider destabilizing. GPT-5.6 showed U.S. labs accepting that constraint. GLM-5.2 showed the same class of capability arriving as open infrastructure, with no one positioned to pull it.<\/p>\n<p>Three practical shifts follow. Plan for adversaries who can read an entire codebase and configuration, not just probe exposed endpoints. Compress patch cycles for known vulnerabilities from quarters to days. And build the in-house capacity, under real governance, to point these models at your own software before someone else does. The question is no longer whether AI gets used against critical systems. It&#8217;s how fast that capability diffuses, and whether defenders keep pace.<\/p>\n","protected":false},"excerpt":{"rendered":"In this photo illustration, a Zhipu AI logo is seen displayed on a smartphone with the Chinese flag&hellip;\n","protected":false},"author":2,"featured_media":88999,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,1731,53,25,47180,912,1129],"class_list":["post-88998","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-andy-jassy","tag-anthropic","tag-artificial-intelligence","tag-buckle-up-the-bad-guys-now-have-a-model","tag-commerce","tag-u-s"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/88998","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=88998"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/88998\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/88999"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=88998"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=88998"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=88998"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}