gg2
checklist.com

Security fix deadline urgent

Archived — this story has rotated out of today’s deck. It is kept here in full.

The gist

GLM 5.3-flash open-weight model released, enabling cheap local dangerous hacking. Security teams face compressed patch deadlines under new CISA BOD 26-04.

Background

The post argues that the release of GLM 5.3-flash, an open-weight AI model, makes dangerous hacking capabilities cheaply available to anyone, as it can be run locally on consumer hardware and modified to remove safety refusals. This coincides with new CISA directives that compress patch deadlines for actively exploited vulnerabilities, pressuring security teams to respond faster.

How it unfolded

  1. recentlyGLM 5.3-flash released by Z.ai, an open-weight model that can be downloaded and modified.
  2. Sep 3, 2026CISA adds 12 CVEs to KEV and issues BOD 26-04, which can compress patch deadlines to three days for high-risk vulnerabilities.
  3. Sep 4, 2026Blog post 'we have a year to fix security everywhere' published, warning of imminent threat from cheap capable models.

Who’s saying what

Author
We have about a year to fix security vulnerabilities before cheap frontier models become widely accessible.
CISA
BOD 26-04 requires federal agencies to patch KEV-listed vulnerabilities within compressed deadlines based on risk.

Still unverified

The claim that GLM 5.3-flash is 'close to the frontier' is based on benchmarks from the vendor and third parties, not independently verified. The exact timeline of 'a year' is the author's estimate.

Sources

See today’s stories in the app gg2 — free on the App Store