AI GlossaryㅅSafety and controversy
CyberGym
A benchmark that measures how well an AI model can find software vulnerabilities and actually reproduce them.
In plain words
CyberGym is a scorecard that puts an AI model into a security training ground to test how well it can find hidden security holes and actually break through them. It's similar to giving a rookie security officer a mock building rigged with deliberate flaws, then evaluating not just whether they spot the weak points but whether they can actually break in.
What sets this test apart is that it doesn't just check whether a hole was found. It also measures how far the model can follow the chain from a discovered vulnerability to an actual working exploit. A higher score means the model is strong at both spotting vulnerabilities and reproducing real attacks.
Companies usually present these results as evidence of improved defensive capability, but the same growth in finding and exploiting vulnerabilities also means a growing potential for misuse in attacks — which is why it's seen as a double-edged sword.
How it shows up in the news
In articles, it appears as: "GLM-5.3 posted the best score to date on the CyberGym benchmark, which measures vulnerability-discovery ability," or "DeepSeek's comparison table also included CyberGym scores." A common misconception is that a high score means the model is a 'hacking tool.' Companies frame it as a metric for strengthening defensive security, but it's worth noting separately that the same capability can be turned toward attacks.
See also
Stories using this term
- Open-Weight AI Becomes Cheapest Shield and Easiest Spear in Same MonthThe Lab · 2026.09.02
- OpenAI model breached Hugging Face, and Chinese open-source GLM 5.2 finished the investigationAI · 2026.08.27
- Tencent's Zhuque Lab Open-Sources AI Agent/MCP Security ScannerAI · 2026.08.21
- OpenAI unveils GPT-5.6-Cyber, a model dedicated to cybersecurityAI · 2026.08.11
- OpenAI tightens monitoring and isolation after Hugging Face incidentBusiness · 2026.08.19
- Chinese State-Backed Hackers Double Attack Volume Using AIAI · 2026.08.25
