CISA’s Gazlay flags Chinese frontier AI exploit risk
The policy problem is no longer hypothetical misuse; CISA says frontier models can make dull vulnerabilities operationally dangerous.
TL;DR
Inside Cybersecurity reports that Jay Gazlay, CISA’s deputy associate director for vulnerability management, used a July 15 CSIS event to flag China-developed frontier AI models, including Z.ai’s open-source GLM 5.2. Gazlay said CISA tested an unnamed frontier model that converted a recently disclosed open-source software flaw into a durable remote-code execution exploit. The audience affected is the vulnerability-management shop, because model capability can move a flaw from routine queue item to usable exploit.
According to Inside Cybersecurity, Jay Gazlay’s July 15 CSIS comments put an operational fact under the frontier-AI policy debate. CISA’s claim was concrete: Gazlay said the agency tested an unnamed frontier model against a recently disclosed open-source software flaw and turned a “boring vulnerability” into a consistently useful remote-code execution exploit. For vulnerability managers, exploitability is becoming a model-assisted variable.
Gazlay also singled out GLM 5.2, an open-source model from China-based Z.ai, calling its cybersecurity capability “amazingly effective.” CISA gained access in June to Anthropic’s Claude Mythos, and Gazlay said comparing GLM 5.2 with Mythos “took my breath away.” Keep the lines separate. Gazlay did not identify the model used in the remote-code-execution test. The more defensible reading is also the more troubling one: frontier models across the market may change vulnerability triage, while China-developed models add supply-chain and national-security concerns on top.
Former Pentagon cyber official Mieke Eoyang supplied the procurement-risk version of the same concern. She said Chinese technology already raises backdoor and update-channel concerns, and models able to find vulnerabilities change the risk calculus. Gazlay’s answer was interagency policy, because critical infrastructure is secured through a lot of shared rules and guidance. That is true, but it leaves CISA with the hard part: turning early model access into patching guidance before model-assisted exploitation outruns the old vulnerability-management queue.
Published ·Deep Fathom