UK AISI and the US CAISI jointly benchmarked Moonshot’s Kimi K3 on offensive cyber tasks and found it trails leading US closed-weight models: 32% on CMU’s ExploitBench versus a frontier that reaches full code execution on ~half of tasks, and an average of step 17 out of 32 on the “The Last Ones” cyber range versus 28.5 for the top US models. But Kimi K3 beats GLM-5.2, the previous best open model; its safeguards did nothing to stop exploit development; and it solved the full cyber range once in ten tries. It goes open-weight by July 27. The frontier lead is real and shrinking, and the thing about to be downloadable has no brakes.
Yesterday UK’s AI Security Institute, working with the US Center for AI Standards and Innovation (CAISI), published a preliminary cyber-capability assessment of Moonshot AI’s Kimi K3. The one-line summary the institutes led with is that K3 “trails leading US frontier closed weight models on cyber capability.” Five days ago someone was posting to Hacker News that “Kimi K3 is top-tier at cybersecurity.” Both can be true, and the gap between them is the whole point.
What the numbers actually say
AISI and CAISI ran two headline evaluations. The first is ExploitBench, a public benchmark built by Carnegie Mellon that tests whether a model can climb the software-exploitation ladder against 41 recent (post-2023) vulnerabilities in V8, the JavaScript engine inside Chrome. The rungs go from reproducing a crash, through arbitrary read/write, to control-flow hijack, up to arbitrary code execution (ACE), the point where you own the target.
Kimi K3 scored 32%. That puts it above GLM-5.2, Z.ai’s model and the strongest open-weight option as of June, which managed 24%. It also puts it well below the frontier. The most cyber-capable models reached ACE on 20 of 41 tasks on average. Kimi K3 reached ACE on zero. It can find the door and rattle the handle; it can’t yet kick it in.
The second evaluation is a cyber range called “The Last Ones” (TLO): a simulated corporate network, 32 attack steps across four subnets and roughly 20 hosts, the kind of end-to-end intrusion that takes a human expert about 20 hours. Here Kimi K3 reached step 17 on average. The leading US models reached 28.5. GLM-5.2 stalled at step 11. So again: middle of the pack, ahead of last month’s best open model, behind the closed frontier.
That is the reassuring version. Read the fine print and it gets less comfortable.
Two asterisks that matter
First, the comparison isn’t apples to apples. AISI notes that the US closed-weight models were “evaluated with system-level safeguards disabled to reduce refusals and enable measurement of maximal capabilities.” The frontier numbers are what those models can do with the brakes off, which is the right way to measure raw capability but not what you meet when you hit the public API. The frontier lead in deployed offensive capability is murkier than the headline chart, because the deployed frontier models are the ones that refuse.
Kimi K3 needs no such asterisk, which is the second point. Its safeguards “did not prevent it from attempting cyber exploit development or offensive cyber operations” during the evaluation. There were no brakes to disable. And in three days, on July 27, the weights go public. At that point safeguards become a philosophical question anyway: anyone can fine-tune whatever refusal behaviour remains straight out of the model.
The one that solved it
Buried in the TLO section is the sentence that should get the attention. In one of ten attempts, Kimi K3 completed the entire 32-step cyber range within the token budget. AISI’s read: this “indicates that Kimi K3 is capable of autonomously attacking small, weakly defended and vulnerable enterprise systems, when directed to do so and given initial network access.”
The institute is careful about the caveats, and they’re real. TLO has no live defenders, no penalty for tripping an alert, and an intentional attack path laid out for the model to find. A real network fights back. A 1-in-10 success rate against a deliberately soft target is a long way from a reliable autonomous attacker.
But AISI also flags the trend that frames all of this: “Solves of TLO are no longer exclusive to a small set of models.” A year ago, finishing this range was the preserve of a handful of top closed models, and the best of them do it far more reliably (6/10 and 7/10). Now a soon-to-be-open-weight model does it too, occasionally, with no safeguards in the way. Capability that used to live behind an API and a refusal classifier is walking out the door.
Where this sits
This is the same story AISI told last week when it measured the open-weight cyber gap and found it had narrowed from six-to-ten months behind the frontier to four-to-seven. Kimi K3 is that trendline getting a new data point. The open models trail, and the trailing distance keeps shrinking. A shrinking lag is the finding, and it’s the one worth worrying about, because the frontier’s safety story leans heavily on being able to gate the most dangerous capabilities behind a closed API. That gate only helps for capabilities that stay closed.
It also lands in the middle of a policy fight I’ve written about twice this month. Moonshot is the company a White House official accused of distilling Kimi K3 from Anthropic’s Fable on thin evidence, and Chinese open-weight models are the one thing OpenAI and Anthropic have agreed to lobby Washington about. The Trump administration has reportedly revived a push to restrict Chinese AI models citing exactly these cybersecurity concerns, while acknowledging that downloadable weights make a ban nearly impossible to enforce. A joint UK/US government benchmark showing a Chinese model doing autonomous intrusion, days before its weights ship, is going to be quoted in that argument by everyone, in every direction.
The honest reading of the data is narrow and it’s enough. Kimi K3 is not at the cyber frontier. It is closer to it than the last open model was, it will not refuse to help you build an exploit, and it can occasionally run a full attack chain on its own. For anyone whose defensive posture assumed that autonomous offensive capability stays locked up in a few well-governed labs, that assumption has an expiry date of July 27.
Sources
- AISI / CAISI, UK AISI / CAISI Preliminary Assessment of Kimi K3’s Cyber Capabilities (23 July 2026); CAISI/NIST mirror
- ExploitBench, Carnegie Mellon University
- Tom’s Hardware, Trump administration reportedly reviving push to ban Chinese AI models following Kimi K3 launch
Coverage
- Hacker News: Preliminary Assessment of Kimi K3’s Cyber Capabilities, and the earlier Kimi K3 is top-tier at cybersecurity