Chinese AI Models Fuel Cybersecurity Concerns as Defenders Fall Behind
A recent surge in advanced artificial intelligence (AI) models from Chinese firms has raised alarm bells among cybersecurity experts, who worry that these cutting-edge tools are widening the gap between attackers and defenders. The two new models, released by Zhipu AI and 360 Security Technology, have demonstrated impressive capabilities in vulnerability discovery, outperforming some of their US-based counterparts.
The open-weight model GLM 5.2, developed by Zhipu AI, has been found to excel in bug-finding benchmarks, even surpassing the likes of Anthropic’s Opus and Open AI’s GPT-5.5. Its cost-effectiveness is also noteworthy, with a price tag of just $0.17 per vulnerability discovered. This model’s success highlights the pressing need for defenders to address their “security debt” – a term coined by Chris Inglis, former US National Cyber Director and strategic advisor for ransomware-defense firm Halcyon.
According to Inglis, defenders must prioritize patching and fixing vulnerabilities in rapid order to stay ahead of attackers. He warns that commodity models like GLM 5.2 can outmaneuver defenses, emphasizing the importance of knowing one’s architecture and addressing weaknesses within it. “Defenses need to get serious about their security posture,” he stresses.
The AI-powered vulnerability discovery process has become increasingly sophisticated, with Chinese models now competing directly with top US models. This development is part of a broader trend in which AI systems are being used by attackers to improve their offense. In April, the Cloud Security Alliance warned that the release of frontier models could lead to an “AI vulnerability storm.” More recently, Google detected its first AI-created exploit being used by an attacker.
Margaret Cunningham, vice president of security and AI strategy at Darktrace, notes that while better models tend to be more reliable, reliability must be weighed against cost, access, speed, and ease of deployment. In practice, both attackers and defenders make economic decisions, she explains. A model simply needs to be good enough to justify its use.
The fact that some Chinese models have open weights – meaning they can be installed on local hardware – presents both opportunities and challenges for defenders. On one hand, this allows companies to adopt these models while keeping data within their network. On the other hand, attackers can experiment with escaping alignment restrictions designed to prevent offensive use.
In conclusion, as AI-powered vulnerability discovery continues to advance, defenders must stay vigilant and address their security debt promptly. The recent releases from Chinese firms have underscored the importance of adopting a proactive approach to cybersecurity, one that prioritizes patching and fixing vulnerabilities before they can be exploited by attackers. By doing so, organizations can mitigate the risks associated with AI-powered attacks and maintain a stronger defense against emerging threats.
Source: Dark Reading — 2026-07-03