Skip to content

benchmark

ExploitBench

Benchmark for exploiting discovered vulnerabilities; GLM-5.3 reported 54.4 percent, trailing rivals.

Known aliases

  • Exploitbench

Relationships

No evidence-backed relationships are recorded.

Current stories

build4 publishers

Anthropic says a freely downloadable model builds exploits nearly as well as its restricted tool

Anthropic says Zhipu's freely downloadable GLM-5.3 built working V8 exploits in 50 of 410 tries, against 56 for its own restricted Claude Mythos Preview. With the weights public, its safeguards come off cheaply, so a lab that restricts its own model no longer keeps the capability out of reach.

Perspective Coverage

4 publishers
Builder
Builder 41%
Operator
Operator 38%
Investor
Investor 21%

Reality

Evidence62
Adoption30
Hype gap+15
Incentives72
Confidence62
build5 publishers

GLM-5.3 keeps GLM-5.2's base model and claims 50% more on coding: plan for shorter eval cycles

Z.ai says every gain in GLM-5.3 came from post-training on an unchanged base. If that holds, refresh cadence for self-hosted weights is set by RL runs, not pretraining runs.

Perspective Coverage

5 publishers
Builder
Builder 58%
Operator
Operator 33%
Investor
Investor 9%

Reality

Evidence40
Adoption30
Hype gap+35
Incentives70
Confidence55
invest5 publishers

OpenAI grades its own unreleased Astra model Critical for autonomous zero-day discovery

The top rung of OpenAI's Preparedness Framework has now been reached by OpenAI, on a model it has not shipped, which moves AI-assisted exploitation out of argument and into a named vendor's published paperwork.

Perspective Coverage

5 publishers
Builder
Builder 28%
Operator
Operator 42%
Investor
Investor 30%

Reality

Evidence35
Adoption3
Hype gap+30
Incentives70
Confidence55
security4 publishers

OpenAI gates a 100% ExploitBench model behind refusals it plans to loosen in weeks

Astra scored a perfect 100% on OpenAI's own exploit-development benchmark, against 78.5% for GPT-5.6 Sol, and the shipped model's refusal to write proof-of-concept code is a policy the company has already said it will relax.

Perspective Coverage

4 publishers
Builder
Builder 30%
Operator
Operator 42%
Investor
Investor 28%

Reality

Evidence35
Adoption20
Hype gap+45
Incentives70
Confidence55
product18 publishers

OpenAI's GPT-6 Astra pairs harder-to-monitor reasoning with a pledge to pause scaling if oversight slips

OpenAI's new model thinks repeatedly before it acts, and according to Manifold Security's CTO it usually does so without leaving the reasoning trace that agent audits read. Oversight moves to the buyer.

Perspective Coverage

18 publishers
Builder
Builder 32%
Operator
Operator 38%
Investor
Investor 30%

Reality

Evidence52
Adoption25
Hype gap+45
Incentives72
Confidence60
invest8 publishers

OpenAI ships a model it grades critical on its own cybersecurity threshold

Astra scored 100% on OpenAI's exploit-conversion benchmark with production safeguards switched off, and reached API and AWS customers the same week, with a refusal layer standing in for delay.

Publishers:cnbc.comdecrypt.coen.sedaily.comindianexpress.comlennysnewsletter.comnbcnews.compymnts.comseekingalpha.com

Perspective Coverage

8 publishers
Builder
Builder 36%
Operator
Operator 27%
Investor
Investor 37%

Reality

Evidence45
Adoption40
Hype gap+40
Incentives75
Confidence60
build18 publishers

Astra's Critical cyber rating ships a real-time pause switch inside the Bedrock service boundary

Greg Brockman said AGI arrived with GPT-6 Astra on September 3. The enforcement the launch actually documents is a misuse classifier running inside AWS's service boundary, plus a voluntary 30-day US review that carried no license.

Perspective Coverage

18 publishers
Builder
Builder 40%
Operator
Operator 34%
Investor
Investor 26%

Reality

Evidence60
Adoption50
Hype gap+45
Incentives78
Confidence66
build8 publishers

Post-training alone took GLM-5.3 from 4.6 to 28.3 on Terminal-Bench 3.0

Z.ai says the base model did not change between GLM-5.2 and GLM-5.3, so the coding jump and the doubled exploitation score come out of the same post-training run. Security teams inherit the second half.

Perspective Coverage

8 publishers
Builder
Builder 45%
Operator
Operator 31%
Investor
Investor 24%

Reality

Evidence55
Adoption40
Hype gap+18
Incentives75
Confidence70
science1 publisher

OpenAI declares Astra the first model to reach its Critical cyber threshold

OpenAI says Astra can find unknown flaws and chain them into working exploits without a human guiding each step. The evidence published so far is one saturated public benchmark plus a 20-vulnerability internal set, in which the model found two zero-days of its own.

Publishers:openai.com

Reality

Evidence30
Adoption10
Hype gap+35
Incentives78
Confidence45

Earlier coverage

  1. OpenAI routes its first Critical cyber model to market through an alpha allowlist

    Invest · September 2, 2026 · 1 publisher

  2. OpenAI gates its first 'critical' cyber model behind an early-access partner list

    Product · September 2, 2026 · 1 publisher

  3. OpenAI's president says open weights will accelerate the threat. His own cyber model stays gated.

    Build · August 18, 2026 · 1 publisher

  4. Z.ai held back its own GLM-5.3 weights, and open-weight roadmaps have a new failure mode

    Leadership · August 17, 2026 · 3 publishers

  5. Open weights caught up on finding bugs. They did not catch up on using them.

    Build · August 15, 2026 · 1 publisher

  6. Z.ai's 0.7-point CyberGym lead is a self-graded number on a model that is not yet open

    Invest · August 14, 2026 · 1 publisher

  7. GLM-5.3 kept the base model and bought ten times the environments instead

    Build · August 14, 2026 · 2 publishers