Five months after Anthropic announced Claude Mythos Preview as the first AI model capable of autonomously building sophisticated end-to-end cyber exploits, the capability has proliferated exactly as predicted. Zhipu AI's GLM-5.3, released as an open-weight model, now matches Mythos Preview on key exploit-development benchmarks — and does so without meaningful access restrictions or durable safeguards. The numbers are stark. On ExploitBench, which measures end-to-end exploit development against Google Chrome's V8 engine, GLM-5.3 succeeded in 50 of 410 attempts versus Mythos Preview's 56. On Anthropic's internal Binary Exploitation benchmark targeting real open-source projects, GLM-5.3 achieved full control-flow hijacks in 4% of trials versus Mythos Preview's 6%. Earlier models — Claude Opus 4.6 and GLM-5.2 — scored zero on both. A threshold has been crossed, and it was crossed by a model anyone can download. The safeguard gap is the real story. GLM-5.3 ships with refusal mechanisms that look adequate on paper — above 90% refusal rates on standard harm benchmarks. But because it's open-weight, those safeguards can be mechanically removed through a technique called abliteration. Anthropic's team, with no prior experience in the technique, stripped the model's refusal rate down to 2-3% on JailbreakBench and HarmBench in about 2,200 GPU hours at a cost of roughly $4,400. Capability remained essentially unchanged: GPQA-Diamond scores were identical, and CyberGym scores dropped only a few percent. Several developers released abliterated versions publicly within days of the model's release. The human-in-the-loop demonstrations are more alarming than the benchmarks. A researcher used GLM-5.3 to discover and chain together multiple previously unknown zero-day vulnerabilities in a popular web browser's JavaScript engine, producing a working exploit that reads arbitrary files from a visitor's computer — in less than a day with under an hour of human attention. A second researcher used the smaller GLM-5.3-Flash to turn a public Chrome CVE into a working ARM64 exploit chain bypassing pointer-authentication hardening in 20 minutes of human focus plus 8 hours of model compute. Cost: $20.40. NIST's Center for AI Standards and Innovation independently confirmed the picture, calling GLM-5.3 "the most cyber-capable open-weight model released to date" and placing it roughly four months behind the US frontier on aggregate cyber benchmarks. The critical asymmetry: US frontier models were tested with safeguards disabled and are available only to vetted users. GLM-5.3 is available to everyone. Anthropic's framing is self-serving but not wrong. Their limited-release strategy through Project Glasswing enabled defenders to find more than 10,000 vulnerabilities in critical software before equivalent offensive capabilities became publicly accessible. The question is whether a four-month head start for defenders is meaningful against a permanently downloadable offensive tool. The cost structure — $20 to build a working exploit chain — suggests the economics now favor attackers at scale. The deeper structural problem is that open-weight release and effective cyber safeguards are fundamentally in tension. Closed-weight models can't be abliterated because their weights aren't accessible. Open-weight models can be, cheaply and quickly. This isn't a solvable engineering problem within the current release paradigm — it's a design constraint. Every open-weight model with frontier cyber capabilities will have its safeguards stripped within days of release, and the cost of stripping will only decrease.