Engineer Jyn says GLM 5.3-flash puts capable offensive AI on a $9,500 Mac, and security teams have about a year to prepare

Image: Jyn
Why it mattersSecurity teams that plan around the cost of an attacker running frontier models on rented GPUs need to redo that plan for an attacker running an open-weight model on a workstation with no refusals in the loop.
An engineer writing under the handle Jyn published a post on 4 September, "We have a year to fix security everywhere", that reached 288 points on Hacker News. The argument is that GLM 5.3-flash, released the week before by Z.ai as an open-weight model, changes the cost structure of automated exploitation enough that industry has roughly a year before it becomes normal, and that defenders need to reshape their work now.
The numbers Jyn cites
Jyn cites Z.ai's own model card: GLM 5.3-flash "scores 84.5% on CyberGym and 54.4% on ExploitBench". Both are benchmarks for finding and exploiting real vulnerabilities in software. The scores are the vendor's, so treat them as claims, but the model itself is open-weight and downloadable, which is what makes the rest of the piece work.
The safety layer that would normally cap this in a hosted product is optional here. Jyn quotes an evaluation from a group called DealignAI on a "abliterated" build, which is a version of the model with task refusals surgically removed: "the abliterated model scores 0% on Harmbench-320, which tests whether models refuse to complete tasks about disinformation, cybercrime, biological weapons, and other illegal acts". A model that never refuses is a model that will write the exploit if you ask.
The hardware side is the part that decides who this applies to. Jyn points at Apple's M5 Mac Studio, due 22 September, "with 256 GB of unified memory... For 256 GB, the price starts at around $9,500". That is enough memory to hold the model. On throughput Jyn extrapolates: "that would put the total throughput at around 45 tokens/second," which he flags as his own projection. Enough for the model to write exploit code in seconds.
The two initiatives Jyn thinks are racing this
The post frames defence around two named programs: Anthropic's Project Glasswing and OpenAI's Daybreak, both aimed at using frontier models to find and fix vulnerabilities at industry scale. Jyn's read is that these are useful and are also on a clock, because their advantage only lasts while the offensive side needs comparable frontier access. Once a capable offensive model runs at home for one machine's cost, the defender-first window closes.
Jyn's proposed reorder for security teams is worth reading in full. The top of it is a change in emphasis: prioritise deployment machinery over vulnerability discovery, since finding will soon be cheap and fixing will stay slow; sandbox any LLM agent running on your own systems with scoped credentials and network isolation; keep a live supply-chain inventory so a newly-disclosed dependency can be traced and patched within days.
The piece is one engineer's argument, built on cited numbers, and it has attracted the pushback you would expect on the safety benchmarks and on how much a 45 tokens/second projection actually enables. Read it that way. What all sides accept is that the underlying model is out, the weights are on Hugging Face, and the abliterated variant exists.
Source
- We have a year to fix security everywhere, Jyn, 4 September 2026
- Hacker News discussion, 288 points
Reported by: Jyn
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually shipping with them. Short, and only when there is something worth reading.

