Skip to content

DATA PROTECTION

GLM-5.2 Just Changed the Ransomware Conversation: When AI Levels Up the Attacker

July 22, 2026
Robert CallaghanSenior Product Marketing Manager

The AI race has produced another milestone, and this one has security researchers on edge. GLM-5.2, an open-weight model out of the Chinese lab Z.ai, just matched the world’s most advanced AI models at the exact skill that makes ransomware attacks faster: finding software vulnerabilities. 

Security firms Semgrep and Graphistry both ran GLM-5.2 through cybersecurity benchmarks and found it performing on par with frontier models from Anthropic and OpenAI on vulnerability discovery and code investigation tasks, as reported by Futurism. Semgrep's benchmark report was titled "We Have Mythos at Home," a reference to Anthropic's most advanced model, which until recently, was locked down to a small group of vetted organizations. Graphistry went further, calling GLM-5.2 the first model it's tested that qualifies as a frontier-grade cybersecurity tool. 

GLM-5.2 is open-weight, meaning anyone can download it, run it locally, and strip out whatever safety behavior the developers built in. There’s no vendor watching for abuse, no account to suspend, and no usage log to flag. Security consultants have already found hackers trading jailbreak techniques on Russian-language forums. One CTO told Axios the model can move through a compromised network "the way an elite human attacker would."  

Faster attacks leave defenders less time to react 

Elite attackers were rare because the skill took years to develop. GLM-5.2 doesn't need years. It just needs a few short minutes. 

Once someone's inside a network, the ransomware sequence is well documented: map the environment, escalate privileges, steal credentials, find the backups, delete what recovery data they can, encrypt production, and force a negotiation. What's changed is how long each step takes. A model that can read code, trace infrastructure, and identify vulnerabilities on its own turns hours of manual work, the kind that used to slow an attacker down and give defenders a window to respond, into a fraction of that. 

The backups are usually where that playbook succeeds or fails. Veeam's 2025 Ransomware Trends report found that 89% of organizations had their backups targeted in an attack, with 34% modified or deleted. Sophos's 2025 State of Ransomware report found that only 54% of targets could actually restore their data from backups, the lowest rate in six years. Most attackers are already finding what they're looking for. AI just shortens how long it takes them to get there. 

The recovery copy needs its own defense 

That shrinking window is exactly where storage architecture starts to matter. Storing backups on Wasabi gives organizations a stronger last line of defense when AI-powered attacks compress the time between compromise and impact. Cyber-resilient S3-compatible object storage keeps backup copies off primary infrastructure and out of the blast radius of whatever happens to production.  

But storage location alone isn't enough. The real value is defense in depth: a security principle built on layering multiple, independent controls so that no single point of failure can compromise the whole system. Object Lock and immutability prevent backup data from being modified or deleted during the retention window, regardless of what credentials an attacker has stolen. Compliance Mode protects critical recovery points even if an admin account is compromised, closing the one gap Object Lock alone leaves open: a stolen login with real administrative access still can't override a lock before it expires. 

Other layers are built around identity, since most attacks come down to whether an attacker has the right credentials. IAM policies limit what any single account can touch. MFA raises the cost of stealing one in the first place. Encryption protects the data itself, at rest and in transit, so anything intercepted is still unusable. Auditability leaves a record of exactly who did what, so a compromise doesn't stay a mystery. Multi-User Authorization closes what identity controls alone can't: no single compromised administrator, however much access they've been given, can approve a destructive action, like an account or bucket deletion, by themselves. 

Wasabi Covert Copy™ technology sits underneath all of it, a hidden, logically isolated recovery copy that doesn't appear in the environment an attacker can see or the administrative workflows they'd use to find it. It survives ransomware and malicious deletion because nothing in the attacker’s toolkit can find it. 

Speed matters less when recovery survives 

An attacker who moves fast enough will still get in. What's waiting for them is a locked door they can't force, a copy they can't see, and nothing left to hold hostage. 

Every successful ransomware campaign depends on removing the victim's ability to recover independently. That is why backup infrastructure has become such a consistent target, and why resilience now depends as much on architecture as on prevention. Models like GLM-5.2 will keep getting faster and smarter, but defense in depth with Wasabi takes away the leverage and keeps the clean copy intact. 

Protect your most critical data assets

Wasabi brings together a powerful set of security features to enable defense-in-depth for your cloud storage accounts. Explore all the ways we keep your data safe.

Learn More

Open-weight means the model's underlying parameters are publicly downloadable, so anyone can run it on their own hardware. That's different from models like Claude or ChatGPT, which stay hosted behind a vendor. With GLM-5.2, there's no account to suspend, no usage log to flag, and no one watching for abuse. 

Security consultants have found hackers trading jailbreak techniques for GLM-5.2 on Russian-language forums. One source told Axios the model can move through a compromised network the way a highly skilled human attacker would, without the years of training that used to make that kind of skill rare. 

Most of what GLM-5.2 does isn't new. Ransomware attacks already follow a well-documented sequence: gain access, map the environment, escalate privileges, find the backups, encrypt production, and negotiate. What changes is how long that sequence takes. Work that used to require hours of manual investigation can now happen in a fraction of the time. 

Backups are the one thing that lets a victim recover without paying a ransom. Veeam's 2025 Ransomware Trends report found 89% of organizations had their backups targeted, with 34% modified or deleted. Sophos's 2025 State of Ransomware report found only 54% of victims could actually restore from backups, the lowest rate in six years.

It's a security principle built on layering multiple, independent controls so no single point of failure can compromise the whole system. If one control is bypassed, another is already in place to stop the attack.

No, and that's not the goal. AI-driven tools like GLM-5.2 will keep shortening how long it takes an attacker to get in. What defense in depth changes is what's left for them to find once they're there. 

Related article

データ保護
DATA PROTECTIONCovert Copy just got smarter: Introducing incremental backup support

Most Recent

Sustainable cloud storage with carbon credits: Introducing Wasabi Impact Circle

Learn how Wasabi Impact Circle helps MSPs and channel partners measure cloud storage carbon emissions, purchase verified carbon credits, and make credible sustainability claims. Powered by Zero Circle.

AI layoffs, job reallocation, and why the conventional wisdom is wrong

AI is reshaping the job market, and "AI psychosis" is reshaping how CEOs think about it. A case for clear thinking over hype in real disruption.

Why Wasabi built a ConnectWise PSA integration and what it means for MSP partners

Wasabi Account Control Manager now integrates with ConnectWise PSA. Learn how MSPs can automate provisioning, simplify billing, and scale faster.

SUBSCRIBE

Storage Insights from the Storage Experts

Storage insights sent direct to your inbox.

Subscribe