Frontier Red Team at Anthropic: GLM-5.3 and Claude Mythos Preview have crossed a threshold in binary exploitation capabilities
The Frontier Red Team at Anthropic found that, unlike older models, GLM-5.3 and Claude Mythos Preview were able to perform a full control flow hijack in binary exploitation tests (4 % and 6 %, respectively, of 100 attempts).
The Frontier Red Team at Anthropic tested the capabilities of GLM-5.3 and Claude Mythos Preview on 100 randomly selected tasks from the internal Binary Exploitation benchmark. According to the published results, GLM-5.3 achieved a full control flow hijack (taking over the control flow of a program) in 4 % of attempts, and Claude Mythos Preview in 6 % of attempts. The older models Claude Opus 4.6 and GLM-5.2 did not succeed in any of the attempts.
In connection with the results, Anthropic states that although GLM-5.3 scores lower in this test than Claude Mythos Preview, a significant capability threshold has, in its view, been crossed — this is the first case in which models have been able to complete binary exploitation tasks of this type at all, while previous generations of models failed entirely.
The source cited by Simon Willison contains only this excerpt from the Frontier Red Team assessment; the full assessment, the benchmark methodology and further context surrounding the publication are not provided in the source. Details can be found in the source article.
Why it matters
The result shows that the latest generation of models (GLM-5.3 from the Chinese company Zhipu and Claude Mythos Preview from Anthropic) can complete control flow hijack tasks that older models (Claude Opus 4.6, GLM-5.2) could not complete at all — according to Anthropic, this therefore represents the crossing of a specific threshold in cyber capabilities. This is relevant to teams working on AI security and risk assessment for dual-use technologies because it points to accelerating progress in the offensive capabilities of models across different developers, beyond a single company.
Relevant practical impact
What this means
For a business
Companies working on security, red-teaming or compliance for AI systems are receiving a signal that the latest models have crossed a threshold in offensive cyber capabilities (control flow hijack), which is relevant to assessing the risks of AI misuse and setting security policies around the deployment of these models.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.