Chinese AI Models Blur the Line Between Attackers and Defenders
In a worrying development for cybersecurity defenders, two new language models from Chinese firms have been released in recent weeks, showcasing capabilities that are outpacing those of their US counterparts. The release of these models has sparked concerns among experts, who warn that they could further widen the gap between attackers and defenders.
The first model, GLM 5.2, was developed by Zhipu AI and released on June 13. It boasts impressive performance in vulnerability discovery, outperforming top US mainstream and frontier models such as Anthropic’s Opus and Open AI’s GPT-5.5 in some benchmarks. Moreover, GLM 5.2 comes at a relatively low cost of $0.17 per vulnerability found, making it an attractive option for attackers.
Just two weeks later, another Chinese firm, 360 Security Technology, released Tulongfeng (aka “Dragon Saber”), a frontier-model-based security tool that its founder claimed had already discovered over 3,400 vulnerabilities. While the capabilities of these models are undeniably impressive, experts warn that they pose significant challenges for defenders.
The key issue is not just the performance of these AI models but also their cost-effectiveness and ease of deployment. According to Margaret Cunningham, vice president of security and AI strategy at Darktrace, an AI cybersecurity platform, even if a model is more reliable, it must be weighed against factors such as cost, access, speed, and ease of deployment. “In practice, both attackers and defenders make economic decisions,” she notes.
The Chinese models’ open weights, meaning they can be installed on local hardware, are also a significant advantage for defenders who need to keep data within their network. However, this same characteristic also enables attackers to experiment with escaping alignment that prevents offensive use. For companies requiring data sovereignty and leakage risks management, the advantages of using Chinese models become apparent.
Yet, experts warn that large language models (LLMs) and other AI architectures have become less significant in the equation. Modern AI systems are now effective enough, especially when combined with the right supporting software, to identify vulnerabilities in many cases. As former US National Cyber Director Chris Inglis notes, “Commodity models can run circles around defenses.” He emphasizes that defenders must prioritize knowing their architecture, identifying weaknesses within it, and rapidly patching and fixing configurations.
The stakes are high, as the release of these AI models has led to concerns about an impending “AI vulnerability storm.” Google recently detected the first AI-created exploit being used by an attacker, highlighting the need for swift action from defenders. As Cunningham notes, “A model just needs to be good enough to justify its use.”
The practical takeaway from this development is clear: defenders must prioritize updating their security posture and taking a proactive approach to addressing vulnerabilities. With AI models becoming increasingly effective in identifying weaknesses, it’s essential that companies invest in patching and fixing configurations as quickly as possible to prevent attacks from succeeding. As Inglis aptly puts it, “I think we’re not past the point of saving ourselves.”
Source: Dark Reading — 2026-07-03