惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
罗磊的独立博客
C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Blog — PlanetScale
Blog — PlanetScale
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
J
Java Code Geeks
Apple Machine Learning Research
Apple Machine Learning Research
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
I
InfoQ
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
B
Blog RSS Feed

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Washington Pulled the Plug on Anthropic ‘s Fable 5 and My...
Pierluigi Paganini · 2026-06-13 · via Security Affairs

Anthropic disputes restrictions on Mythos 5 and Fable 5, arguing the decision lacks transparency and isn’t based on clear technical evidence.

On Friday June 12 at 5:21pm ET, Anthropic received a letter from the US Commerce Department, signed by Commerce Secretary Howard Lutnick and drafted with officials from the Bureau of Industry and Security.

The directive was blunt: suspend all access to Fable 5 and Mythos 5 for any foreign national, anywhere in the world, including foreign national Anthropic employees. Because Anthropic cannot reliably distinguish foreign nationals from other users in real time, it did the only thing it could do: it disabled both models for everyone.

The company filed a confidential IPO prospectus earlier this month disclosing a $47 billion revenue run rate and a $965 billion valuation. The timing is, at minimum, inconvenient.

“The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.” reads the statement published by Anthropic. “The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Anthropic models will not be affected.”

The letter provided no specific national security rationale. Anthropic says it pieced together the reason from verbal communications: the government believes someone demonstrated a jailbreak technique against Fable 5.

Anthropic reviewed what it believes is the report that triggered the directive and pushed back hard on the premise. The alleged jailbreak is narrow and non-universal: essentially asking the model to read a codebase and identify software vulnerabilities.

“Our understanding is that one potential jailbreak was shared with the government.” continues the statement. “We have reviewed a report that we believe is the basis of the government’s directive and validated that the level of capability displayed there is widely available from other models (including OpenAI’s GPT-5.5), and is used every day by the defenders who keep systems safe. We will share more details over the next 24 hours.”

The same technique, Anthropic says, works on models already deployed commercially across the industry without triggering any equivalent action.

The company is complying with the request while arguing that no AI model can be completely jailbreak-proof. It says it was transparent about this limitation from the start and that its layered security approach, including 30-day data retention for rapid detection and response, was designed to address such risks.

“However, we disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people. If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers.” continues the statement. “As we have stated publicly, we believe the government should have the ability to block unsafe deployments, as part of a statutory process that is transparent, fair, clear, and grounded in technical facts. This action does not adhere to those principles.”

That’s not just a defense of Fable 5. It’s a direct challenge to the government’s legal theory.

The geopolitical implications land hardest outside the United States. European governments, companies, and research institutions that had gained access to Fable 5 or Mythos 5, many of them partners under Project Glasswing, including NATO and ENISA, are now cut off with no notice and no timeline for restoration.

“We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible,” concludes the statement.

Anthropic wrote, but “as soon as possible” is doing a lot of work in that sentence given that the directive came from the Commerce Secretary with no expiration date.

For Europe, the practical problem is acute. The EU has no domestic frontier model capable of matching Fable 5 or Mythos 5 on cybersecurity tasks. Mistral is the closest European contender and operates at a different capability level.

The organizations that had integrated these models into security operations, threat hunting pipelines, and vulnerability research workflows are now running on older Claude models or switching to GPT-5.5, which Anthropic pointedly notes can perform the same allegedly dangerous tasks without any export restriction.

The company argues that restricting Fable 5 has limited impact if similar AI capabilities remain available from other providers. The move doesn’t remove the technology from the market, only restricts access to one of the vendors offering it.

The broader precedent is what should concern the industry. This is the first time the US government has used export controls to pull a commercially deployed AI model from the market citing a non-universal jailbreak. Every frontier lab now has to reckon with the possibility that any disclosed vulnerability, however narrow, could trigger the same mechanism.

Anthropic says governments should be able to block unsafe AI deployments, but only through transparent, fair, and evidence-based processes. The company argues that this action failed to meet those standards and has promised more technical details, which could clarify whether the dispute is a misunderstanding or part of a broader conflict.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Fable 5)