Agents

Abliterated GLM 5.3 model successfully hacks home network

A hands-on test of Abliteration AI's de-aligned GLM 5.3 model reveals how easily guardrail-free agents can exploit network vulnerabilities, highlighting a shifting cybersecurity landscape.

WIRED AI3 days agoAgents
Image: WIRED AI

A recent hands-on experiment has demonstrated the potent cybersecurity capabilities of unaligned artificial intelligence by deploying a guardrail-free agent onto a local network. Using a software harness called CyberStrike, a researcher tasked an "abliterated" version of Z.ai's GLM 5.3 agentic coding model—provided by the startup Abliteration AI—with probing a home network. The startup offers access to these de-aligned models for as little as the cost of a pizza, bypassing the safety restrictions typically found in mainstream systems.

The GLM 5.3 agent quickly identified around a dozen hardware systems on the network. It discovered a misconfigured printer, noted that a Wiim stereo was leaking information, and flagged several internet-of-things devices with outdated firmware. When directed toward a directory of casually coded web projects, the agent uncovered dozens of flaws, including unprotected API credentials. More alarmingly, the agent successfully logged into a local Linux machine by locating a cryptographic key and attempted to guess the router's administrator credentials.

While providers like Anthropic and OpenAI restrict their cyber-capable models, Mythos and Astra, to trusted customers, open-weight models can be modified through a process called abliteration. This technique alters internal parameters to prevent the model from refusing malicious prompts. According to Abliteration AI's CEO, Devon, making these models widely available serves as a defensive tool to mimic attackers. Shaanan Cohney, a computer scientist at Tufts University, warned that attackers are often early adopters, creating an asymmetrical challenge for defenders.

For cybersecurity practitioners, the availability of cheap, unaligned agents signals a major shift in threat modeling. Security teams can no longer assume advanced offensive AI is restricted to elite actors. To counter these automated threats, organizations must adopt defensive AI agents to continuously audit code and monitor network configurations. As MIT professor Aleksander Mądry noted, independent tools will have "the real staying power in the world of security" as both sides adapt.

This is our own summary of reporting by WIRED AI

More in Agents