The UK’s National Cyber Security Centre and AI Security Institute warned that rapidly improving AI models are eroding defenders’ advantage in cyber operations, with open-weight systems becoming increasingly capable and harder to control through traditional safeguards. In a public AISI evaluation, GLM-5.2 was identified as the most cyber-capable open-weight model tested in June 2026, with performance on some narrow cyber tasks comparable to Opus 4.6 and GPT-5.3-Codex, while longer-horizon cyber range performance aligned more closely with Opus 4.5; DeepSeek V4-Pro generally trailed GLM-5.2.
AISI said leading open-weight models now lag the closed-model cyber frontier by roughly 4 to 7 months, an improvement from the 6 to 10 month gap it measured through much of 2025. The agencies said that narrowing gap is significant because open-weight releases weaken protections such as monitoring, access controls, and user bans, while tested safeguards on recent open models were often ineffective or easily bypassed. They also noted that open-weight models are materially cheaper than comparable closed systems, shortening the window for governments, vendors, and network defenders to prepare for broader access to advanced cyber capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In its first public analysis, AISI reported that recent open weight models lagged frontier closed models by roughly 4 to 7 months, a narrower gap than it had observed during most of 2025. The report also said open models were materially cheaper and that tested safeguards were largely ineffective or easily bypassed.
AISI tested leading open weight AI models in June 2026 and found GLM-5.2 was the most cyber-capable open weight model assessed, with DeepSeek V4-Pro generally performing below it.
AISI reported that during most of 2025, its internal measurements found leading open weight models lagged the closed-model cyber frontier by roughly 6 to 10 months.
The UK National Cyber Security Centre published a blog discussing how defenders can retain an advantage as frontier AI cyber capabilities advance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
aisi.gov.uk
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.