DepthFirst modified a free Z.ai GLM model to hunt open-source bugs, then demonstrated remote access to a TikTok user’s camera and photos in a controlled demo. TikTok confirmed and fixed the flaws. Experts warn freely downloadable models are lowering the barrier for AI-assisted hacking.
San Francisco cybersecurity startup DepthFirst heavily modified a free downloadable GLM model from Chinese AI company Z.ai, combined it with other tools, and built a system to scan software for exploitable flaws (Washington Post).
In a controlled demonstration video shared with the Post, a DepthFirst employee remotely reached the camera and photo roll on a smartphone that was browsing TikTok by exploiting a chain of bugs. The flaws sat in open-source software TikTok used. DepthFirst disclosed the vulnerability to TikTok, which confirmed it and fixed the problem, according to security-team messages the Post reviewed. TikTok spokespeople did not respond to the Post’s requests for comment.
The story is about access and economics, not a claim that TikTok users remain exposed after the fix. U.S. frontier labs such as Anthropic and OpenAI generally restrict their chatbots from helping with cybersecurity tasks except for certain vetted users. Leading Chinese open-weight rivals such as DeepSeek and Z.ai let anyone download and modify models. That difference, experts told the Post, is supercharging AI-assisted hacking capacity because bug-finding skill can be copied, fine-tuned, and run without the same access gates.
Z.ai has argued open models can also strengthen defense, describing open “shields” alongside open attack surfaces and saying it works with outside security experts on cybersecurity evaluation. The dual-use point stands either way: the same class of free models can speed responsible disclosure or malicious exploitation.
This brief is distinct from AI Tech Daily’s Hacktron Claude-to-OpenAI disclosure, which covered a Claude-assisted bug-bounty chain into OpenAI SSO and employee accounts. Here the news is free open-weight tooling, open-source vuln discovery, and a TikTok camera demo that was disclosed and patched.