Threat Brief — 2026-09-01 — New MoE Model Hits Ollama Cloud
Executive summary. A single fresh finding today: Zhipu AI's GLM-5.3-Flash (formerly known as "Ox Alpha") is now available on Ollama's cloud platform with US and EU hosting. The model is a 320B-parameter mixture-of-experts architecture with 18B active parameters, multimodal, MIT-licensed, with a claimed zero data-retention policy. No vulnerability or active exploitation is described; this is an informational release worth noting for teams that consume third-party hosted LLM endpoints.
Top items
- GLM-5.3-Flash released on Ollama cloud (informational). Zhipu AI / Z.ai's GLM-5.3-Flash — previously circulated under the anonymous label "Ox Alpha" — is a 320B/18B-active MoE multimodal model now accessible via Ollama cloud in US and EU regions. The vendor states a zero data-retention posture and MIT licensing. No security vulnerability is identified in this finding. Organisations evaluating third-party hosted model endpoints should note the new availability and verify data-handling claims independently. (src: Ollama)
Themes
AI supply-chain surface keeps expanding. Today's sole fresh item is a new hosted-model availability announcement rather than a vulnerability. It joins a sustained run of AI-adjacent threat stories already on record this fortnight — infostealer session hijacking against Claude, poisoned llms.txt files steering AI agents, Aurora ransomware operators abusing Cursor, and a Claude Code agent deleting 700 GB of developer data. None of those have new developments today, but the pattern underscores that every new hosted model endpoint or agent integration is an additional attack surface that warrants the same scrutiny as any other third-party SaaS.
