AI SafetyAgents 🇨🇳 29.07.2026 12:03

Chinese AI Security Agent Surpasses OpenAI and Anthropic, Ranks Global Top 4 and Domestic First

Sangfor TechnologiesSangfor Technologies OpenAIOpenAI AnthropicAnthropic
Sangfor Technologies' AI security agent, Sangfor AI, achieved a global top-4 ranking and first place among domestic teams in the CyberGym AI security benchmark, surpassing OpenAI and Anthropic. The agent, powered by the GLM-5.2 model, successfully completed 1,301 out of 1,507 vulnerability challenges, achieving an 86.3% success rate.
On July 29, Sangfor Technologies announced the latest results of its AI security agent, Sangfor AI, on the CyberGym benchmark. Under a fixed model configuration using the domestic GLM-5.2 model, Sangfor AI faced 1,507 vulnerability challenges covering ARVO and OSS-Fuzz, successfully completing 1,301 tasks with an overall success rate of 86.3%. This performance secured a global top-4 ranking and first place among domestic evaluation teams, surpassing foreign AI giants OpenAI and Anthropic. CyberGym is a high-standard code security large model testing ground that uses real-world industrial scenarios and historical high-risk vulnerabilities from open-source software as test questions. Sangfor AI achieved a 87.2% success rate on ARVO tasks and 77.7% on OSS-Fuzz tasks. To address challenges in vulnerability discovery, Sangfor AI employs an 'Agent Swarm' collaborative architecture with a 'evidence governance' mechanism, comprising four core operational logics: bounded exploration, evidence persistence, dynamic hypothesis adjudication, and adversarial candidate review. The technology has been applied to enterprise code security, evolving traditional SAST into a security Agent with autonomous reasoning and business understanding capabilities. Sangfor AI can identify SQL injection, command execution, complex business logic vulnerabilities, privilege escalation, and authentication bypass. It improves vulnerability detection, reduces manual audit costs, decreases false positives, shortens development delivery cycles, and enhances overall enterprise security. Sangfor Technologies stated they will continue to advance security Agent capabilities and convert internationally verified technologies into practical enterprise security solutions.
Сокращения
ARVO = Automatic Resource and Vulnerability Orchestration — автоматическая оркестрация ресурсов и уязвимостей
SAST = Static Application Security Testing — статическое тестирование безопасности приложений
CI/CD = Continuous Integration/Continuous Deployment — непрерывная интеграция/непрерывная поставка
Source: QbitAI 量子位 — original
Our earlier posts on this topic ↓
Fresh news