惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Cloudflare Blog
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
博客园 - 司徒正美
V
Visual Studio Blog
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
aimingoo的专栏
aimingoo的专栏
博客园_首页
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
S
SegmentFault 最新的问题
T
The Blog of Author Tim Ferriss
D
Docker
Vercel News
Vercel News
Recent Announcements
Recent Announcements
Last Week in AI
Last Week in AI
爱范儿
爱范儿
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
U.S. Commerce Dept Imposes Export Controls on Anthropic's...
Guru Baran · 2026-06-17 · via Cyber Security News

The Bureau of Industry and Security (BIS) has issued a landmark “Is Informed” letter to Anthropic CEO Dario Amodei, mandating that the company obtain an individually validated export license before sharing its Claude Mythos 5 and Claude Fable 5 AI models with any foreign national anywhere in the world.

In a letter signed by Commerce Secretary Howard W. Lutnick, BIS invoked the Export Control Reform Act of 2018 (ECRA), specifically 50 U.S.C. § 4817(b)(1), which empowers the agency to establish interim controls on emerging and foundational technologies essential to U.S. national security.

The order also relies on § 744.22(b) of the Export Administration Regulations (EAR), 15 C.F.R. Parts 730–774, which authorizes BIS to require export licenses whenever there is an unacceptable risk of use in, or diversion to, a “military-intelligence end use” or a “military-intelligence end user”. This marks the first time the Commerce Department has exercised this particular ECRA provision against a commercially available AI model.

Global Lock to Claude Mythos 5 and Fable 5

The BIS directive covers any export, reexport, or in-country transfer of the Claude Mythos 5 and Fable 5 models, including deemed exports and deemed reexports. Practically, this extends to:

  • Sending or taking the model out of the United States in any manner (§ 734.13(a)(1) of the EAR)
  • Sending or taking the model from one foreign country to another (§ 734.14(a)(1) of the EAR)
  • Retransferring the model within a single foreign country (§ 734.16 of the EAR)
  • Releasing the model to a “foreign person” inside the United States — including non-citizen Anthropic employees

Anthropic received the directive on June 12, 2026, at 5:21 PM ET, just three days after the models launched on June 9, and immediately disabled global access to both.

The catalyst for this unprecedented action appears to be a reported jailbreak vulnerability in Fable 5 that could bypass its safety filters, potentially exposing the advanced cybersecurity capabilities embedded in the underlying Mythos 5 framework.

Mythos 5 is particularly capable of identifying software vulnerabilities, including long-hidden flaws in production codebases, and was originally intended for exclusive use by government entities and select enterprise partners. Anthropic contends that the identified bypass only surfaces “minor” security flaws also discoverable by other publicly available frontier models.

More than 80 cybersecurity executives and experts including leaders at Nvidia and Adobe signed an open letter to Secretary Lutnick urging the administration to lift the restrictions, backing Anthropic’s position that the threat is overstated.

To continue operations, Anthropic must now submit license applications through the Simplified Network Application Process Redesign (SNAP-R) portal (snapr.bis.gov), noting the “Is Informed” letter in the Additional Information field. Failure to comply carries prompt criminal and civil penalties under U.S. law.

The EU Commission has already warned that the controls “should not be discriminatory,” signaling potential diplomatic friction. The restrictions also affect foreign nationals on H-1B visas working at U.S. AI firms, raising significant workforce and enterprise access concerns.

The BIS letter states the license requirements remain in effect until superseded by a subsequent letter from BIS revising or rescinding the order. This action sets a defining precedent for how the U.S. government may regulate advanced AI as a dual-use technology under export control law going forward.

CISO & Security Leaders: Your next breach may not have a face. Join ISC2’s LIVE webinar, “Ghost in the Machine” – Book Your Spot Here

Guru Baran

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.