GLM-5.3 lands: a frontier coding model that found 2,436 real bugs

Z.ai's coding model rivals Claude via API now; open weights land end of August, 53 CVEs already disclosed. Plus: Claude Code adds cross-session @-mentions.

Nowline AUG 14 11:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • Coding that trades blows with Claude, at fewer tokens

    On Z.ai's own Code Bench, GLM-5.3 edges Claude Opus 4.8 — 31.4% at ~50k tokens versus Opus's 29.5% at 120k — and lifts Terminal-Bench 3.0 from 4.6 to 28.3, first among open models but still behind Claude Fable 5. Every figure is vendor-reported until independent runs land.

  • A bug-hunting skill nobody trained for

    Z.ai says that as it scaled vulnerability-finding training, the model began chaining full exploitation plans on its own — then surfaced 2,436 flaws across 269 open-source projects (1,097 critical or high), the oldest dating to 1981. 53 CVEs are public now; 2,383 stay under embargo.

  • Use it today; self-host in two weeks

    GLM-5.3 is live now via Z.ai's API, the GLM Coding Plan, and the ZCode harness, built on the same base as GLM-5.2. Open weights follow around end of August after a safety review — the deliberate two-week gap is Z.ai flagging its own offensive-capability worry.

  • Elsewhere: Claude Code sessions can @-mention each other

    v2.1.232 (Aug 13) flips subagent forking on by default — forks inherit your full conversation and prompt cache — and lets you type @ to hand a task to another running session. Plugin marketplaces now clone from GitLab too.