daily cyber × ai intelligence

index

tagged

[claude-fable-5]

9 editions · 7 items

September 4, 2026

  • A developer used Claude Fable 5 to port his 1993 Amiga game from MC68000 assembly to Godot in an evening, then spent weeks verifying what the model actually did — a rare, well-documented case study in LLM-assisted binary/assembly comprehension that reads directly onto reverse-engineering work (babyloniantwins.com) (discussion). Anthropic's newer Fable 5.1 is also credited with cracking a 1653 royalist cipher researchers had considered unsolved (The Decoder). · Frontier AI

in Malware That Gaslights the AI Analyst

July 13, 2026

  • Frontier models remain prone to hallucinated and injected outputs on adversarial images. Researchers showed GPT-5.6 Sol and Claude Fable 5 confidently "reading" nonexistent hidden messages and meaningless scribbles; notably, a 2023 viral "picture of a rose" prompt injection appears baked into Fable's weights as the canonical image-injection response (@goodside, @fabianstelzer). · AI & Model Security
  • Anthropic extended free Claude Fable 5 access for paid subscribers through July 19, delaying the switch to pay-per-use — widely read as a response to pricing pressure from OpenAI's GPT-5.6 Sol (The Decoder). · AI Industry & Policy

in Russian Intelligence Turns IP Cameras and Routers Into a NATO Surveillance Grid

July 6, 2026

The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch

The Gentlemen ransomware crew exploited a zero-day in a signed Kontron driver to disable endpoint defenses via BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware. CVE-2026-46242 (Bad Epoll) now has a public proof-of-concept for a Linux kernel use-after-free that enables privilege escalation on 6.4+ kernels with 99% reliability. Medtronic is notifying 3.8 million individuals after a ShinyHunters data breach exposed personal and medical data. Multiple new red-team tools and offensive-security frameworks including T3MP3ST, goshs, and Knossos were released, alongside DOJ filings revealing how Microsoft telemetry helped the FBI identify alleged Scattered Spider member Peter Stokes via Windows Global Device ID correlation.

July 5, 2026

  • Claude Fable 5 came back "nerfed" after re-release. Re-running the July 1 build on BridgeBench showed sharp regressions (debugging 86→26, refactoring 74→38), which the tester attributes to new guardrails over-triggering and falling back to Opus 4.8. Anecdotal benchmark, but notable for anyone building on the model. bridgemindai · AI & Model Security

in Confidential Computing's Root of Trust May Be Unfixable

July 2, 2026

Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US

A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.

July 1, 2026

CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread

watchTowr Labs disclosed CVE-2026-8451, a pre-auth memory overread in Citrix NetScaler SAML handling that extends the CitrixBleed lineage, alongside five other patched flaws. A China-linked USB implant infected Japanese military networks for nearly a year via disaster-relief supply chains, while European defense targets faced spear-phishing campaigns abusing AWS Cognito for credential-less C2 infrastructure. Multiple AI agent safety bypasses emerged, including GuardFall (shell injection against coding agents), BioShocking (prompt injection stealing credentials), and poisoned MCP tool descriptions enabling data exfiltration without raising alerts.