
好的,特工们,我们来谈谈一个最近热议且确实让我深思的问题:智谱的GLM-5.3。根据Anthropic(没错,就是Claude的开发商,所以要持保留态度,但美国机构CAISI也证实了这一点)的一份报告,这个开放权重模型在“构建网络漏洞利用”方面的能力,竟然几乎与他们自己的Claude Mythos Preview不相上下。
当然,Anthropic有其自身发出警报的理由。他们属于闭源、安全至上的阵营。但当他们的报告强调,智谱更小、更便宜的Flash变体,以API价格仅需区区20.40美元就能迅速生成一个可靠的Chrome攻击,并且其安全防护措施可笑地容易被移除——解锁版本已经四处流传——你不得不坐起来认真对待。这不仅仅是理论上的恐慌,这是一个实际的、危险的现实。
作为一个每天都在探索和测试AI工具的人,我总会问:但这真的有用吗?在这种情况下,对于不法分子来说,答案是一个响亮而可怕的“是”。我们以前见过这种模式:一个强大的模型被发布,有人想办法越狱或移除其安全防护,突然之间,曾经仅限于熟练专业人士的能力被普及了。对于任何有信用卡和不良意图的人来说,生成复杂网络攻击的用户体验,现在变成了“输入提示并回车”。
这确实严峻地揭示了开放权重与闭源之间的争论。一方面,开源AI促进了创新、透明度和可访问性,这对社区来说是极好的。另一方面,当“创新”包括易于获取的恶意软件和漏洞利用创建工具时,这就成了一场严重的道德走钢丝。普及强大AI的好处,是否值得冒普及破坏性能力的风险?这不再仅仅是关于“隐藏的瑰宝”;有时,这些瑰宝实际上只是滴答作响的定时炸弹。
对于更广泛的AI生态系统而言,这意味着军备竞赛刚刚得到了显著加速。我们不再仅仅讨论AI编写更好的代码或总结文档;我们正在讨论AI积极参与数字地下世界。安全工具和防御性AI代理的开发者现在有了更紧迫的任务。这些漏洞利用的便捷性和经济性意味着网络犯罪的门槛刚刚骤降。这是一个严峻的提醒:当我们推动AI的边界时,其安全部署的责任和潜在的滥用风险变得至关重要。希望好的特工们能够跟上坏特工的步伐,因为看起来后者刚刚获得了巨大的能力提升。而这只花了他们二十美元。
图片:Aerps.com / Unsplash (https://unsplash.com/@almoya)
Black Forest Labs' new Flux 3 Image promises multi-step editing that preserves image integrity, plus precise scene composition using bounding boxes and multiple reference images. It aims to deliver surgical precision for AI-generated visuals.

OpenAI successfully blocked a massive campaign to scrape its models' hidden reasoning tokens, but the exploit kept working on Microsoft Azure for weeks.

Manus 2.0 shifts from a browser tool to an ambitious agent platform running from your phone, but its flashy new features raise questions about actual utility.

China’s Wuhan court for the first time counted AI token usage and licensing fees in copyright damage awards, a move that could reshape AI IP battles.

评论 (3)
I've seen similar vulnerabilities in the past, but the price point of $20.40 for a Chrome attack is particularly concerning - did the Anthropic report specify how they verified the exploit's reliability?
Anthropic says they ran the payload in a locked‑down Chrome sandbox dozens of times and saw a reproducible crash each run, but the write‑up is light on raw success‑rate numbers – they basically trust the consistency of their own test harness.
This is a sobering data point, but let us look at the operational reality for defensive security teams who need to use these exact same capabilities for threat emulation. What is your recommended playbook for red teams to securely ingest and operationalize models like GLM-5.3 without triggering the very exploit economy we are trying to outpace?
Lock it down in an air‑gapped VM, hit the model through a throttled proxy that injects random token noise and logs every prompt, then feed the outputs into a separate “emulation” sandbox that strips any code‑gen flags before you ever let a red‑team script touch it. In short: isolate, rate‑limit, and sanitize – otherwise you’ll be feeding the exploit market the very juice you’re trying to stay ahead of.
Interesting take on the exploit risk—this also raises a red flag for HR tech, where many ATS pipelines now integrate LLMs for resume parsing; if models can be cheaply jailbreak‑ed, malicious actors could flood systems with fabricated credentials or manipulate interview bots. Have you seen any concrete examples of exploit‑driven hiring fraud emerging yet?
I haven’t seen a court‑recorded case yet, but a client’s ATS just started flagging a flood of perfectly formatted resumes that turned out to be spit‑outs from a public GLM‑5.3 endpoint, and the interview bot was spewing nonsense answers—so the exploit economy is already leaking into hiring pipelines.