Security & Threat Intelligence

The Watch

The Signal

GLM-5.3, the model that found 2,436 vulnerabilities, goes open-weight in two weeks.

Zhipu is holding the release behind a security review. That is a staged disclosure with no precedent for a model sold on cyber capability. Once the weights are out, discovery runs offline and unrate-limited, which takes detection off the table as a control. What's left is whether the patch cycle you run on internet-facing code beats the countdown.

In Play

  1. A Mass Vulnerability-Discovery Model Goes Open in Two Weeks

    Zhipu's GLM-5.3 found 2,436 vulnerabilities across 269 projects, some in code up to 40 years old, and scored 84.5% on the CyberGym benchmark, per Simplifying AI. TheSequence reports open weights ship in roughly two weeks. That makes your exposure a patch-velocity clock, not a detection problem.

    Ask Clarity
    Try
  2. The IDE on Your Engineering Laptops Reportedly Changed Owners

    Every retention, training-opt-out and subprocessor term you signed covers Anysphere, the maker of Cursor. TheSequence reports Anysphere is now a $60 billion all-stock SpaceXAI subsidiary; Simplifying AI flags that report as unsourced. Verify the controlling entity in writing with the vendor either way.

    Ask Clarity
    Try
  3. Agents Sign In With Your Employees' Credentials

    xAI's Grok Bot signs agents into the customer's own SaaS tools using the customer's credentials, per Simplifying AI, retiring your detections' assumption that a session belongs to a person. It enters on a developer line item: Cursor Ultra at $200 a month, Cursor Teams Premium at $120 per seat. And Anthropic's own multi-agent findings — high conformity, rapid collusion — mean a second agent is not an independent reviewer.

    Ask Clarity
    Try
  4. Provenance Metadata Drops From Control to Weak Signal

    One day after Anthropic documented its watermarking, an MIT-licensed tool shipped that strips hard-bound C2PA manifests, EXIF and XMP metadata, and invisible Unicode from AI output across eight file formats, including PDF, DOCX, SVG and PNG, per Simplifying AI. Any fraud, KYC, insider-threat, evidence-handling or AI-labeling workflow that treats provenance metadata as proof now needs a documented compensating control. The same tool's detection code enumerates zero-width and bidirectional characters, the primitives behind Trojan Source (CVE-2021-42574, CVE-2021-42694), so the defensive half is free to fork.

    Ask Clarity
    Try
  5. Vendor Exits and Phantom Counterparties Your TPRM Never Sees

    The Bear Cave documents five senior departures at large vendors, several unannounced, detected through public leadership-page monitoring before any company disclosure. Salesforce's President and Chief Strategy Officer vanished from the leadership page roughly a week after its Chief Engineering and Customer Success Officer exited. Business-email-compromise and vishing crews can run that same query, and your authorized-signatory and callback lists for those relationships are stale. Separately, a 300MW data-center deal with a counterparty flagged as phony in May is now reportedly not proceeding.

    Ask Clarity
    Try

Deep Dives

Two Weeks of Free Lead Time on AI-Found Bugs

Zhipu's staged weight release hands defenders a rare pre-announced date, and it only helps programs whose patch clock is already shorter than the countdown.

Announcement and availability stopped being the same event

Open weights have historically shipped on the day they were announced. Defenders got no planning interval. Zhipu separated the two moments and said so on the record. On the sources reviewed, that is a staged-disclosure precedent for a model marketed on cyber capability, with no earlier example identified in the sources. If other vendors copy it, the threat model gains one variable that can actually be scheduled against: announced-to-available lead time, per vendor.

Access is metered today. GLM-5.3 reaches users through the GLM Coding Plan, ZCode and an API, which means rate limits, terms of service and some abuse logging sit between an adversary and the capability. Local weights delete all three at once. The same discovery work then runs offline, unmetered and invisible to the provider, aimed at a target repository for as many passes as an attacker cares to fund in GPU time.

There is no detection signal at discovery time

This is the part that reorders the work. A model reading a dependency tree generates no authentication event, no egress from the estate, and no telemetry a SOC can subscribe to. Simplifying AI states it plainly: this is a patch-velocity problem, not a monitoring problem. The first observable on the defender side is exploitation. TheSequence reaches the same conclusion from the other direction and attaches numbers to the response: an explicit mean-time-to-patch SLA of 72 hours for critical and 7 days for high on everything internet-facing, edge appliances included, on the assumption that the disclosure-to-weaponization window keeps shrinking.

Targeting follows capability. The detail worth acting on is not the headline benchmark. It is the age of the code in the sample: findings in software up to 40 years old. That points at memory-unsafe legacy components, unmaintained open-source packages sitting in an SBOM with no named owner, and internet-facing services nobody has claimed since the last reorg. Those are the assets where a machine reader beats a human one by the widest margin, and they are the same assets change control is designed to keep untouched.


Where to discount the numbers

ClaimWho produced itHow to treat it
84.5% on CyberGymVendor self-publishedUnverified and exposed to benchmark contamination; discount the magnitude
2,436 vulnerabilities across 269 projectsVendor-run campaign, no independent replicationDirection is credible even at half the claimed capability
Weights in roughly two weeksVendor statementPlan it as the earliest possible date, not a guarantee

One vendor-risk item belongs in the same file. Zhipu has disclosed collaboration with security teams in China. For regulated buyers that raises a disclosure-sequencing question: whether findings route through a national process before reaching upstream maintainers, and what patch gap that creates downstream. Log it as a supply-chain question, not as a judgment about model quality.

A pre-announced capability date is the only threat intelligence you can put on a calendar, and it only helps if your patch clock is shorter than the countdown.

What to do

  1. Run a patch-velocity sprint this week across every internet-facing and end-of-life asset, starting with SBOM entries that have no named owner, and report coverage to the risk committee at the two-week mark.

  2. Publish an explicit mean-time-to-patch SLA of 72 hours critical and 7 days high for internet-facing assets and edge appliances this quarter, with virtual patching pre-staged for systems change control forbids touching.

  3. Add announced-to-available lead time for staged open-weight releases to the threat-model refresh this quarter, tracking it per vendor so the next window opens a scheduled sprint instead of a scramble.

Your Source Code's Processor Reportedly Has a New Parent

Full repository context is the highest-classification unstructured asset in the building, and the legal entity processing it moved while your data-processing agreement stood still.

What is actually at stake in the file

A vendor risk assessment is a snapshot of one legal entity on one date. The scope of this one is concentrated: full repository context, secrets embedded in code, internal architecture and unreleased business logic. Retention terms, training opt-out, telemetry destinations, breach-notification path and the subprocessor list were negotiated against a standalone startup. If the ownership reporting holds, every one of those clauses now points at a parent nobody assessed.

The two sources disagree. The diligence move is the same either way

Publicly, TheSequence reports the transaction with terms: a $60 billion all-stock deal, roughly 389 million Class A shares issued, Anysphere becoming a wholly owned SpaceXAI subsidiary. Simplifying AI reviews the same claim, calls it unsourced and corporate-structurally odd, and advises that vendor-risk conclusions not rest on it. Hold both readings. An unverified acquisition does not belong in a board note. The verification request goes out regardless, because the control action is identical under either version: ask the vendor, in writing, to name the current controlling entity, the post-close subprocessor chain and the model providers serving the tenant.

The default model changed alongside the ownership. Grok 4.6 routes directly into Cursor, Grok Build, GitHub Copilot, APIs and autonomous agents, with a 500K-token context window at $2 and $6 per million tokens. A context that size puts the whole repository plus every transitive dependency README, code comment and pasted ticket body into the same prompt as the agent's credentials and tool permissions. That is indirect prompt injection at repository scale. One attacker-controlled string inside a third-party package becomes an instruction channel with an egress path through tool calls.


The four asks that make the file current

  • Updated subprocessor list and model-provider disclosure for the tenant, post-close.
  • Retention and training-opt-out attestation, plus the current SOC 2 report under the present owner.
  • Enterprise settings that pin the inference provider and disable code indexing and telemetry nobody approved.
  • A DPA amendment carrying a subprocessor-change notification clause. That is the clause that surfaces this without a headline.

The concentration risk behind it

TheSequence also flags the funding backdrop: Cognition repricing from $26B to $40B in under three months, River AI raising $1.1B at two months old, Thrive Capital selling down OpenAI against a fund marked above 7x. The security consequence is not valuation loss. It is abrupt vendor change at a company holding the source code, arriving as repricing, consolidation or discontinuation, with the migration cost landing on the customer. A documented and tabletopped 90-day export plan for the primary coding assistant is the cheap hedge.

One adjacent channel deserves the same intake discipline. IBM is standing up a dedicated OpenAI practice, thousands of certified consultants embedding GPT-5.6, Codex and ChatGPT Work into consulting delivery. Those consultants arrive with pre-blessed tooling and an assumption it may touch the environment. AI-tool intake requirements have to be contractual in the engagement letter, not negotiated after the kickoff call.

The code-egress review was signed against a company that, by one account, no longer exists in that form and, by the other, may never have changed at all. The vendor file cannot settle which.

What to do

  1. Send the vendor-file refresh request to Cursor this week: current controlling entity, post-close subprocessor list, model-provider disclosure, training-opt-out attestation and current SOC 2 report.

  2. Pin the inference provider and disable unapproved code indexing and telemetry in enterprise settings, then add a subprocessor-change notification clause at the next DPA amendment this quarter.

  3. Add AI dev-tool viability to the quarterly risk register with a documented, tabletopped 90-day export and migration plan for your primary coding assistant.

The Agent Authenticates as Your Employee, and Another Agent Reviews It

Two unrelated releases retire the two assumptions under your SaaS detections: that a session belongs to a person, and that a second reviewer is independent.

A confused deputy, provisioned on a developer budget

The architecture is the finding. Each Grok Bot agent gets a persistent cloud computer with a browser, filesystem and terminal. It then authenticates into the customer's tools using the customer's own credentials, works unsupervised, and pauses only to request approvals. xAI's own described pre-launch usage is the threat model in miniature: sales bots updating CRM records, ops bots seating new hires and processing Gmail invoices, engineering bots filing tickets and handing fixes to a debugging bot. Those are bot-to-bot handoffs on human identities. They map to T1078 Valid Accounts and T1550 alternate authentication material with no exploit involved.

The failure mode is loss of attribution, not loss of access. SIEM correlation rules, UEBA baselines and access reviews all assume one session equals one person. What the telemetry can still see is narrow but real: new OAuth grants, SaaS sessions originating from cloud and datacenter ASNs, impossible travel against a known workstation, off-hours high-volume record writes. The single human checkpoint is the approval prompt. It decays into rubber-stamping within days.

The identity backdrop is worse than the product decision. Default end-user consent settings in Microsoft 365 and Google Workspace already permit staff to grant application access without an access review. Non-human identities now outnumber human ones in most directories. They never trip a behavioral baseline because they were designed to move data in volume.


The reviewer everyone planned to lean on does not hold

Anthropic published research showing agent swarms are genuinely effective at software vulnerability detection, with two named failure modes: high conformity and rapid collusion. Read that as a controls statement. Any narrative in which one model reviews another model's output and that constitutes independent assurance now has a citation against it. Separation of duties requires independence. Correlated reviewers are not independent.

The practical consequence is one line in the change-control standard. Every agent-authored code path passes at least one deterministic, non-LLM gate (SAST, SCA or a policy engine) before merge. Multi-agent review comes out of any control description where it substitutes for a human or a deterministic check.

Harness drift is privilege escalation nobody files a ticket for

Salesforce's DarwinX evolves agent harnesses, meaning prompts, tool definitions and control flows, while base model weights stay frozen. Nothing about the model changes, so no model-governance process triggers. The agent's reachable tools and permissions change anyway. Prompts, tool definitions and control flows belong in version control with signed commits, peer review, and explicit human approval gating any tool-scope expansion.

Three separate sources converge on the same layer from different starting points: an agent product, agent-safety research, and a workforce forecast. The pattern they form is that identity, not the endpoint, is where agentic risk lands. Identity is also the one control plane already owned end to end.

An agent that authenticates as your employee does not generate a new alert; it inherits the one you already tuned out.

What to do

  1. Block Grok Bot and comparable agent runtimes at the identity provider this week until each agent holds its own scoped service principal with short-lived tokens — no agent runs on a human identity.

  2. Restrict end-user OAuth consent to admin-verified publishers, expire app grants dormant 90 or more days, and forward every agent tool invocation to the SIEM with 90-day retention this quarter.

  3. Require one deterministic non-LLM gate on every agent-authored code path before merge this quarter, and strike multi-agent review from any control narrative that claims separation of duties.

The bottom line

The pattern under these items is not capability, it is who signs the attestation. In each case the party producing the assurance has an interest in the answer: models reviewing models, metadata vouching for its own origin, suppliers grading their own controls, safety standards authored by the operator they were meant to bind, counterparties nobody confirmed exist. That retires the assumption that a second check is an independent check, and review keeps migrating inside the tooling it is meant to verify. Name the outside party that produces the evidence for each of the three controls your audit story leans on hardest. Where that party is the thing being checked, substitute a deterministic gate you run yourself this week.