For some cybersecurity tasks, the Chinese models are already good enough, things like PoC development or things like exploiting mis-configurations.
Whilst I'm sure the top-end OpenAI/Anthropic models might be better, I've found their guardrails so twitchy (especially Anthropic) that I wouldn't try to use them for even vaguely security related work.