Kimi K3 Raises Cyber Stakes for Critical Infrastructure
Moonshot AI's 2.8-trillion-parameter Kimi K3 has intensified debate over whether Chinese open-weight models create distinct security risks. Open weights can be self-hosted, keeping data inside an organization and reducing reliance on foreign cloud APIs, but they also allow users to remove safeguards and repurpose cyber capabilities. The central vulnerability is not open-source technology alone. It is the fragmented ability of governments, model developers and operators of energy, finance and communications systems to share intelligence, patch weaknesses and coordinate responses when attackers target critical infrastructure.
On July 23, the UK Artificial Intelligence Security Institute and the U.S. Center for AI Standards and Innovation said Kimi K3 reached step 17, on average, in a 32-step simulated corporate-network attack, versus 28.5 for leading U.S. models. K3 completed the full path in one of 10 attempts and achieved arbitrary code execution in none of 41 ExploitBench samples. Moonshot released K3 on July 16 and scheduled its full open-weight release for July 27, sharpening calls for coordinated threat sharing, patching and incident response before such capabilities spread.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.