Skip to content
worth noting Security

Frontier Red Team at Anthropic: GLM-5.3 and Claude Mythos Preview have crossed a threshold in binary exploitation capabilities

only one source so far

The Frontier Red Team at Anthropic found that, unlike older models, GLM-5.3 and Claude Mythos Preview were able to perform a full control flow hijack in binary exploitation tests (4 % and 6 %, respectively, of 100 attempts).

The Frontier Red Team at Anthropic tested the capabilities of GLM-5.3 and Claude Mythos Preview on 100 randomly selected tasks from the internal Binary Exploitation benchmark. According to the published results, GLM-5.3 achieved a full control flow hijack (taking over the control flow of a program) in 4 % of attempts, and Claude Mythos Preview in 6 % of attempts. The older models Claude Opus 4.6 and GLM-5.2 did not succeed in any of the attempts.

In connection with the results, Anthropic states that although GLM-5.3 scores lower in this test than Claude Mythos Preview, a significant capability threshold has, in its view, been crossed — this is the first case in which models have been able to complete binary exploitation tasks of this type at all, while previous generations of models failed entirely.

The source cited by Simon Willison contains only this excerpt from the Frontier Red Team assessment; the full assessment, the benchmark methodology and further context surrounding the publication are not provided in the source. Details can be found in the source article.

What changed

Why it matters

The result shows that the latest generation of models (GLM-5.3 from the Chinese company Zhipu and Claude Mythos Preview from Anthropic) can complete control flow hijack tasks that older models (Claude Opus 4.6, GLM-5.2) could not complete at all — according to Anthropic, this therefore represents the crossing of a specific threshold in cyber capabilities. This is relevant to teams working on AI security and risk assessment for dual-use technologies because it points to accelerating progress in the offensive capabilities of models across different developers, beyond a single company.

Relevant practical impact

What this means

01

For a business

Companies working on security, red-teaming or compliance for AI systems are receiving a signal that the latest models have crossed a threshold in offensive cyber capabilities (control flow hijack), which is relevant to assessing the risks of AI misuse and setting security policies around the deployment of these models.

Risks and compliance
What to decide Monitor developments in assessments of the cyber capabilities of frontier AI models as part of corporate risk management and security policies for deploying AI tools.
More business impacts →
AI bezpečnost Anthropic Frontier Red Team Binary Exploitation Claude Mythos Preview control flow hijack GLM-5.3

Check the original

Event sources

only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.

1
Simon Willison — AI tag (leading independent LLM commentator) community signal · first detected Quoting Anthropic Frontier Red Team