SECURITY
New AI Model Finds Serious Security Flaw in Cursor Before Public Release
Before most people had even heard its name, a new AI model called GLM-5.3 had already done something that security teams at major software companies get paid full salaries to do — and apparently did it better.
GLM-5.3, developed by the Chinese AI lab Zhipu AI, reportedly identified a serious vulnerability in Cursor, the wildly popular AI-powered code editor, before the tool even shipped the affected feature publicly. That is not a minor footnote. That is the kind of outcome that changes how the security industry thinks about AI's role in the vulnerability discovery pipeline.
For context, Cursor has become one of the fastest-growing developer tools in recent memory. Developers use it to write, edit, and debug code with AI assistance, which means a serious security flaw baked into its infrastructure is not an abstract risk — it is a direct line to the codebases of thousands of companies. Finding that flaw before public release was genuinely valuable work.
GLM-5.3 is positioned as a model with advanced cybersecurity capabilities, meaning it was explicitly trained and evaluated on tasks like penetration testing, vulnerability research, and threat analysis. This is a category of AI that makes a lot of people nervous, and for understandable reasons. A model that can find vulnerabilities can, in the wrong hands, also exploit them.
That dual-use tension is not new in security tooling, but it gets sharper when the tool in question can operate at machine speed and scale. Traditional security researchers work within legal and ethical frameworks, take time, and have reputations on the line. An AI model has none of those natural governors unless they are deliberately engineered in.
Zhipu AI's approach here seems oriented toward the defensive side — positioning GLM-5.3 as a tool that helps developers and security teams catch problems before attackers do. The Cursor example is a strong proof point for that pitch. But the same capability set that flagged a flaw in a popular IDE could theoretically be pointed at any software target.
What makes this moment worth paying attention to is less about GLM-5.3 specifically and more about what it signals for the broader trajectory of AI in security. We are moving from a world where AI assists security researchers to one where AI conducts independent security research. The humans are increasingly in a supervisory role.
For enterprises and software teams, the practical takeaway is uncomfortable but important: if an AI model can find serious vulnerabilities in your product before you ship it, someone else's AI model can probably find them after. The race between offensive and defensive AI in cybersecurity just got a very concrete example to point to.
Source: VentureBeat
SCIENCE
Largest All-Electric Aircraft Completes First Test Flight for Just Five Dollars
A plane roughly the size of a regional airliner just took off, flew for nearly half an hour, and landed — and the total energy bill came to five dollars. Let that sit for a moment.
Heart Aerospace's X1 demonstrator completed its maiden flight on August 12 at Plattsburgh International Airport in upstate New York, marking a genuine milestone in electric aviation. The aircraft can reach a maximum takeoff weight north of 25,000 pounds, powered by four wing-mounted electric motors that together delivered more than one megawatt of power during the flight. It is the largest battery-electric aircraft ever to fly, and it did so at a fuel cost that would not cover a grande latte.
The timing is not incidental. Jet fuel prices have surged dramatically in the wake of the US conflict with Iran, which has injected fresh urgency into the question of whether commercial aviation can reduce its dependence on geopolitically sensitive fuel supplies. A plane that runs on grid electricity sidesteps that exposure entirely.
But here is the thing — Heart Aerospace is not actually planning to sell an all-electric commercial aircraft. The X1 is a research vehicle, and so is the follow-on X2 model the company has planned. The real product is the ES-30, a 30-seat hybrid-electric regional airliner that combines electric motors with conventional turboprop engines running on jet fuel.
That hybrid configuration is the pragmatic concession to physics that pure electric aviation still cannot escape. Current battery technology limits all-electric range to roughly 100 to 200 miles, which is fine for air taxis but falls well short of the short-haul corridors that regional airlines actually need to serve. The ES-30 is designed for 125 miles of fully electric flight and up to 500 miles in hybrid mode, which opens up a genuinely useful slice of the route map.
United Airlines has committed to purchasing 100 ES-30 aircraft, and Air Canada and Mesa Air Group have also invested in Heart Aerospace's development program. United's CFO offered a statement that was carefully enthusiastic — acknowledging the potential while stopping well short of calling this a revolution. That measured tone is probably appropriate given that commercial certification is not targeted until 2031.
Heart Aerospace started life as a Swedish startup and has since relocated to Los Angeles, where it is building the first pre-production ES-30. Flight testing on that aircraft is expected to begin in 2028.
The $5 flight is a headline-grabbing data point, but the more durable story is what it represents architecturally. The X1 test is generating real-world performance data that feeds directly into the ES-30's design. Every kilowatt-hour measured, every motor stress test logged, reduces the uncertainty in the vehicle that airlines are actually going to operate. The cheap flight is the proof of concept. The hard part starts now.
Source: Ars Technica