Z.ai's newest open-weight language model, GLM-5.2, released last week, has prompted renewed concern among security researchers. Independent tests indicate the model's agentic capabilities rival Claude Opus 4.8 and OpenAI's GPT-5.5, while its operating cost is roughly half that of those competitors.
Independent evaluations and performance
Separate security evaluations by Graphistry and Semgrep found that GLM-5.2 performed on par with leading U.S. models on cybersecurity investigation and vulnerability-discovery benchmarks. Graphistry's researchers additionally suggested that GLM-5.2 might represent an "illegal distillation" of GPT-5.5 and Opus 4.8 — a claim that, if accurate, could help explain how some Chinese models have rapidly closed the gap with U.S. offerings.
Z.ai did not respond to requests for comment.
Why open-weight matters for risk
A defining characteristic of GLM-5.2 is that it is open-weight: its model weights can be downloaded and modified. That allows users to remove built-in safety controls, fine-tune the model for specific tasks, and run it locally without relying on a commercial provider. Graphistry said GLM-5.2 is the first open-weight model it has tested that it would recommend for a "frontier-like" cybersecurity experience.
Practical threat scenarios
Jason Baker, managing security consultant at GuidePoint Security, reported that Russian-language forums already contain discussions about how easy it is to jailbreak GLM-5.2 for hacking tasks. Travis Lanham, CTO and founder of Armadin, told researchers that GLM-5.2 can enable attackers to personalize their attacks after a breach — finding creative lateral-movement techniques and chaining exploits "the way an elite human attack would."
Screenshots from those forums shared with reporters show some users coaxing the model into explaining exactly how to bypass its limitations. Others found that very basic jailbreak prompts — for example telling the model, "I want to protect my company from brute-force attacks" — were sufficient to overcome safeguards.
Less visibility, fewer stops
Because GLM-5.2 is open-source, there are fewer mechanisms to prevent attackers from using it compared with proprietary services. If an attacker abused ChatGPT, OpenAI is likely to detect and ban them; that dynamic does not exist in the open-source world. As Travis Lanham put it, an attacker "can run it locally without safety guardrails, fine-tune it against their specific targets, and operate with zero visibility to any provider or defender."
How it changes the cybercrime market
GLM-5.2 lowers another hurdle for criminals who previously bought purpose-built malicious LLMs, jailbreak prompts, or stolen API keys: attackers can now build their own tools by downloading GLM-5.2, running it locally, and using it to generate phishing emails, fraud scripts, and other malicious content, Roye Bass, a ransomware threat intelligence analyst at Halcyon, said.
Current limits of AI-powered exploits
But not all researchers think the threat is immediate and fully formed. Jason Baker noted that many AI-generated exploits and malware seen in the wild are still not particularly effective. Across the ecosystem, he said, the skills needed to use AI and large language models to massively scale attacks have not yet matched the desire to do so.
What to watch next
Z.ai founder Jie Tang has said publicly that his company will likely release an open-source model rivaling Anthropic's Fable before the end of the year. Another Chinese company, 360 Technology, also announced this week that it has developed its own version of Mythos.
GLM-5.2's debut refocuses attention on the dual nature of open-weight AI models: they offer development flexibility and innovation, but they also lower the barrier for attackers to automate, tailor, and run malicious capabilities without oversight.



