‼️Anthropic's Claude Fable 5 Jailbroken to Generate Stack Exploits
Source: https://t.co/nYCDWchCkO
Anthropic launched Claude Fable 5 on June 9, 2026, as the first publicly available model in its new Mythos class, its most capable AI to date, excelling in software engineering, knowledge work, and vision benchmarks.
Researcher "Pliny the Liberator" defeats Claude Fable 5's safety classifiers using multi-agent decomposition, Unicode tricks, and narrative framing, leaking the model's 120,000-character system prompt along the way.
Screenshots shared by Pliny showed detailed outputs, including step-by-step stack buffer overflow exploitation guidance for x86 Linux systems, including disabling ASLR, writing vulnerable C server code with strcpy overflows, and compiling without protections — as well as the Birch reduction mechanism, a classic meth synthesis pathway.
#cybersecuritynews
There is a lot of traffic from this IP exploiting Unifi firewalls (if they have their management ports exposed to the internet, why do people do this?)
The FBI is warning Microsoft users about a device-code phishing scam, called Kali365, in which cybercriminals use legitimate Microsoft login pages to trick victims into granting access to Outlook, Teams, OneDrive & Microsoft 365 accounts. IC3 PSA here: https://t.co/BD8aLciar0
🛡️ Instagram Fixes Password Reset Flaw That Exposes User Emails & Phone Numbers
Source: https://t.co/lYrZTqMWc4
A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those belonging to high-profile individuals such as Meta CEO Mark Zuckerberg and model Georgina Rodriguez.
Instagram’s parent company Meta deployed an emergency hotfix within hours of the disclosure, but not before proof-of-concept screenshots circulated widely on social media, demonstrating the scope of the vulnerability.
#cybersecuritynews
Yup, this has been going on for the past couple of months!
⚠️ Instagram Lookups: your email, phone number, and location can all be seen.
Masking emails and phone numbers during password recovery when you can just display them in full?
Account recovery or account discovery?
Can Meta explain?