September 4, 2026
- A developer used Claude Fable 5 to port his 1993 Amiga game from MC68000 assembly to Godot in an evening, then spent weeks verifying what the model actually did — a rare, well-documented case study in LLM-assisted binary/assembly comprehension that reads directly onto reverse-engineering work (babyloniantwins.com) (discussion). Anthropic's newer Fable 5.1 is also credited with cracking a 1653 royalist cipher researchers had considered unsolved (The Decoder).
· Frontier AI
in Malware That Gaslights the AI Analyst
July 13, 2026
- Frontier models remain prone to hallucinated and injected outputs on adversarial images. Researchers showed GPT-5.6 Sol and Claude Fable 5 confidently "reading" nonexistent hidden messages and meaningless scribbles; notably, a 2023 viral "picture of a rose" prompt injection appears baked into Fable's weights as the canonical image-injection response (@goodside, @fabianstelzer).
· AI & Model Security
- Anthropic extended free Claude Fable 5 access for paid subscribers through July 19, delaying the switch to pay-per-use — widely read as a response to pricing pressure from OpenAI's GPT-5.6 Sol (The Decoder).
· AI Industry & Policy
in Russian Intelligence Turns IP Cameras and Routers Into a NATO Surveillance Grid
July 6, 2026
The Gentlemen ransomware crew exploited a zero-day in a signed Kontron driver to disable endpoint defenses via BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware. CVE-2026-46242 (Bad Epoll) now has a public proof-of-concept for a Linux kernel use-after-free that enables privilege escalation on 6.4+ kernels with 99% reliability. Medtronic is notifying 3.8 million individuals after a ShinyHunters data breach exposed personal and medical data. Multiple new red-team tools and offensive-security frameworks including T3MP3ST, goshs, and Knossos were released, alongside DOJ filings revealing how Microsoft telemetry helped the FBI identify alleged Scattered Spider member Peter Stokes via Windows Global Device ID correlation.
July 5, 2026
- Claude Fable 5 came back "nerfed" after re-release. Re-running the July 1 build on BridgeBench showed sharp regressions (debugging 86→26, refactoring 74→38), which the tester attributes to new guardrails over-triggering and falling back to Opus 4.8. Anecdotal benchmark, but notable for anyone building on the model. bridgemindai
· AI & Model Security
in Confidential Computing's Root of Trust May Be Unfixable
July 4, 2026
- Claude Fable 5 returns "nerfed." Anthropic says Fable 5 will leave subscription plans after July 7 but return outside usage-based pricing; independent BridgeBench re-runs show sharp drops (debugging 86.2→25.9, refactoring 73.6→38.4) that testers attribute to new guardrails falling back to Opus 4.8. BleepingComputer
· AI & Model Security
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat
July 3, 2026
- Anthropic said the US Department of Commerce lifted export controls on Claude Fable 5 and Mythos 5, and it is restoring access. Anthropic.
· Policy & Regulation
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire
July 2, 2026
A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.
July 1, 2026
watchTowr Labs disclosed CVE-2026-8451, a pre-auth memory overread in Citrix NetScaler SAML handling that extends the CitrixBleed lineage, alongside five other patched flaws. A China-linked USB implant infected Japanese military networks for nearly a year via disaster-relief supply chains, while European defense targets faced spear-phishing campaigns abusing AWS Cognito for credential-less C2 infrastructure. Multiple AI agent safety bypasses emerged, including GuardFall (shell injection against coding agents), BioShocking (prompt injection stealing credentials), and poisoned MCP tool descriptions enabling data exfiltration without raising alerts.
June 18, 2026
- Anthropic was ordered by the U.S. government to abruptly suspend access to its top Claude Fable 5 and Mythos 5 models for all foreign nationals, citing national security — a notable precedent for export-style controls on frontier models (The Hacker News).
· Industry & Policy
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel