AI-Driven Cyber Threats Surge as Open-Source Models Lower Attack Barriers
The rapid proliferation of open-source AI models from Chinese firms like Z.ai has lowered barriers to cyberattacks, as demonstrated by a startup exposing TikTok vulnerabilities.

The global cybersecurity landscape is undergoing profound turmoil amid the rapid development of artificial intelligence tools, which now allow not only the protection of computer systems but also the execution of complex attacks with unprecedented speed and ease. While major U.S. companies like Anthropic and OpenAI have chosen to impose strict limits on their chatbots and grant access to advanced cyber tools only to approved and supervised entities, the global market paints a starkly different picture.
Leading competitors in China, particularly firms like Z.ai and DeepSeek, allow any user worldwide to download, modify, and run open-source AI models without cost or substantive restriction. This open approach theoretically empowers security experts attempting to preempt vulnerabilities, but simultaneously drastically lowers the barrier to entry for cybercrime and provides potential hackers with access to highly advanced technological knowledge.
TikTok Breach and Red Flags
A prominent example of the potential inherent in these systems was recently revealed by a local cybersecurity startup, DepthFirst. The company utilized a customized, upgraded version of the free GLM artificial intelligence model from Chinese firm Z.ai to build an automated bug-and-flaw detection system.
In a demonstration video, security researchers showed how the AI-trained system successfully identified a chain of security flaws within an open-source component used by the popular video application TikTok.
By exploiting these vulnerabilities, researchers gained full remote access to the camera and photo gallery of a smartphone running the app. It must be emphasized that the action was performed strictly in an internal testing environment and no real users were harmed; TikTok was notified of the findings via its traditional bug bounty program and quickly patched the flaw.
Nevertheless, the case illustrates the complex reality keeping leading security managers awake at night. Qosim Mitani, CEO of DepthFirst, admitted that such activity is precisely what robs him of sleep, as high accessibility to open and powerful models is expected to spawn a new wave of threats that are difficult to anticipate in advance.
Dramatic Surge in Global Vulnerabilities
Additional cybersecurity and research figures share this concern. International organizations and security firms such as Palo Alto Networks (via its Unit 42 division) report unrelenting workloads and a surge of thousands of new vulnerabilities discovered in open-source projects thanks to automated AI-based tools.
Concurrently, government bodies and national security officials report a tenfold increase in security vulnerabilities identified in critical organizations, as state-sponsored espionage groups (such as hackers linked to Russian intelligence agencies) utilize similar tools to generate adaptive malicious code capable of bypassing defense systems.
These developments place the average consumer in an entirely new reality. Security experts warn that traditional rules—such as avoiding suspicious emails or maintaining strong passwords—are no longer sufficient to ensure full protection. The latest recommendation for users is to exercise extreme caution, maintain routine software updates for applications, and minimize to the absolute necessary minimum the permissions granted to various apps to access the camera, location, or photo gallery on mobile devices.





