China's GLM-5.3 Matches Frontier Labs at Finding Software Flaws
China’s GLM-5.3 Matches Frontier Labs at Finding Software Flaws
AI & Machine Learning
Chinese developer Z.ai released GLM-5.3 on 14 August, and Reuters reports the open-source model came close to Anthropic’s restricted Mythos 5 in tests measuring the ability to identify software vulnerabilities. The company says the release reuses the GLM-5.2 base model entirely, deriving its gains from scaled-up post-training rather than a fresh pretraining run — an unusually cheap path to a frontier-adjacent result. Z.ai is positioning it as the most capable open-weights model for coding, shipping first through its GLM Coding Plan and ZCode before reaching the API and Hugging Face. The cyber-capability result is the part drawing attention, because an openly downloadable model that can find exploitable flaws does not stay confined to defenders. It lands the same week OpenAI restricted its own comparable capability behind a vetting process. Source: Reuters Verified: True
OpenAI expanded its Daybreak cybersecurity programme into two access tiers and introduced GPT-5.6-Cyber, a model trained specifically for vulnerability research, exploit validation and penetration testing. Daybreak Blue covers general defensive work while Daybreak Red gates the more permissive model behind vetting, reflecting that the same capability serves attackers and defenders equally well. OpenAI reports the model completed 95% of advanced cybersecurity task requests in testing, with pricing set at $12.50 per million input tokens and $75 per million output. The company frames the release around a narrowing window between when a flaw becomes findable by AI and when it becomes exploitable at scale. Access has since been extended to eligible AWS customers through Amazon Bedrock. Source: OpenAI Verified: True
Consumer Hardware
Google held its Pixel event on 12 August and shipped the full Pixel 11 lineup alongside the Pixel Watch 5, converting months of leaked renders into confirmed hardware. Beyond the phones themselves the announcements centred on new camera processing and health-tracking features, the areas where Google has been leaning on on-device models to differentiate from spec-comparable rivals. The launch settles the earlier foldable speculation with shipping product rather than marketing imagery. For buyers the more consequential detail is the watch, which extends Google’s push to make Pixel a bundle rather than a single handset purchase. Source: The Verge Verified: True
Apple is reportedly restructuring its iPhone release calendar, with the base iPhone 18 pushed out of the traditional autumn window and into early 2027. Staggering the lineup would break a launch cadence Apple has held for over a decade, separating the premium models from the entry tier by several months. The reported motivation is smoothing manufacturing and demand rather than any technical delay in the base model itself. If it holds, buyers waiting on the cheapest current-generation iPhone face an unusually long gap, and Apple’s autumn event loses the volume product that traditionally anchors it. Source: The Verge Verified: True
Global wearable band shipments fell 2% year over year in the second quarter of 2026 according to new Omdia figures, but the headline number conceals a split in what people are actually buying. Demand is moving toward screenless trackers at the budget end and advanced sports watches at the premium end, hollowing out the mid-range smartwatch that dominated the category for years. That barbell pattern suggests the general-purpose wrist computer is losing ground to devices with a sharper single purpose. For vendors it complicates roadmaps built on the assumption that every wearable eventually becomes a smartwatch. Source: Business Wire Verified: True
Cybersecurity
Attackers are actively exploiting CVE-2026-59310, a critical VMware vCenter flaw that allows arbitrary code execution, with exploitation observed since earlier this month. Researchers warn that patching alone may not fully mitigate the threat, implying attackers who established a foothold before the fix can persist through it. vCenter is a high-value target because compromising it hands an intruder control of the virtualization layer beneath many workloads at once. Organisations that patched are being advised to hunt for prior compromise rather than assume the update closed the incident. Source: SecurityWeek Verified: True
The ShinyHunters group exploited a CVSS 9.8 zero-day in Oracle PeopleSoft, tracked as CVE-2026-35273, to breach more than 100 organisations, most of them universities. PeopleSoft is widely deployed for student records, HR and payroll, so a compromise reaches directly into concentrated personal data. Universities are a recurring target for this class of attack because large PeopleSoft deployments often lag on patching. The scale here comes from the flaw being weaponised before a fix existed rather than from slow patching alone. Source: tech-insider.org Verified: True
Framework disclosed a data breach after attackers exploited a zero-day in its hosted Metabase instance, showing how business-intelligence tooling becomes an attractive target precisely because it is wired into everything. Metabase sits on top of production data by design, so access to it can be equivalent to access to the underlying databases without ever touching them directly. The same Metabase flaw was reported against other organisations in the same disclosure window. The incident is a reminder that analytics layers inherit the sensitivity of the data they query while frequently sitting outside the security review applied to the primary systems. Source: Help Net Security Verified: True
Microsoft warned that a China-linked threat actor is exploiting a critical vulnerability in N-able software to turn a widely deployed security and remote-management tool into a ransomware delivery mechanism. Tooling of this kind holds privileged access across every endpoint it manages, so subverting it converts a defensive product into the most efficient possible distribution channel. Managed service providers are the natural blast radius, since a single compromised console can reach many downstream customer estates. The pattern of targeting the management layer rather than individual endpoints continues to be the most efficient route to scale for ransomware operators. Source: The Record Verified: True
Enterprise Infrastructure
Quantinuum and Oracle announced a multi-year strategic partnership to bring hybrid quantum computing to Oracle Cloud Infrastructure, letting customers combine quantum processors with classical OCI compute in a single workflow. The hybrid framing matters more than the quantum hardware itself, because near-term useful work involves a quantum processor handling a narrow subproblem while classical infrastructure does everything around it. Putting that behind a standard cloud console lowers the barrier from specialist research access to ordinary enterprise procurement. It follows a broader pattern of hyperscalers treating specialised compute as another instance type. Source: Quantinuum Verified: True
IBM and Together AI signed a multi-year agreement to run large-scale open-source AI inference on IBM Cloud using NVIDIA HGX B300 systems, described as the first cluster of its kind for the partnership. The deal targets enterprises that want to run open-weight models at production scale without building GPU infrastructure themselves. Positioning around open-source inference rather than proprietary model access is a deliberate contrast with rivals whose AI story runs through a single frontier lab. It also gives Together AI distribution into IBM’s enterprise base. Source: IBM Newsroom Verified: True
Vantage Data Centers and Nebius announced their first deployment in the South Wales AI Growth Zone, expanding UK AI infrastructure under a designation intended to concentrate compute buildout in specific regions. Growth-zone schemes work by pre-clearing the planning and grid-connection obstacles that otherwise dominate data-centre timelines. Siting capacity in South Wales rather than the saturated London corridor reflects how power availability now drives location decisions more than network proximity. It is an early test of whether the designation actually shortens delivery. Source: Business Wire Verified: True
Policy & Regulation
The Federal Trade Commission issued a proposed policy statement on AI accuracy and output steering, focusing on models that push users toward undisclosed ideological objectives. The framing treats undisclosed steering as a potential consumer-protection problem rather than a speech question, which places it inside the FTC’s existing deception authority instead of requiring new legislation. That choice matters because it makes the standard enforceable now against model providers and the businesses deploying them. Combined with emerging state AI chatbot laws and existing wiretapping statutes, operators face a compliance surface assembled from several unrelated bodies of law. Source: The National Law Review Verified: True
A new roundup of California’s 2026 technology bills catalogues how far the state has moved to fill the gap left by the absence of comprehensive federal frameworks. California’s scale means its rules function as de facto national standards, since few companies build a separate product for one state. The breadth of the session’s bills spans AI disclosure, privacy and platform obligations rather than concentrating on a single flagship measure. For companies tracking AI regulation, the practical near-term constraint continues to arrive from Sacramento rather than Washington. Source: Reason Foundation Verified: True