We're open sourcing a 9B model that extracts structured data from documents at near-frontier performance.
- 90.2% on our bench, vs Gemini 3.5 Flash at 91.3%
- Leads extraction models like NuExtract3 (81.5%)
- 9.5s p50 timings
- Pass JSON schema
As a result of a US government directive, we are suspending access to Claude Fable 5 for all users. You can continue to use all other Claude models.
Here’s what this means for you:
Across Claude products, new sessions will run on your selected default model or Opus 4.8, and existing Fable 5 sessions will end with an error.
On the Claude Platform, requests to Fable 5 will also return an error. Please update your integrations to other Claude models.
We know this is a disruption to your workflows; we appreciate your patience and support.
Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use.
Its capabilities exceed those of any model we’ve ever made generally available.
Google releases Gemma 4 QAT. ✨
You can now run Gemma 4 at 3x less memory with near original performance.
Quantization-Aware Training (QAT) makes it possible to run Gemma 4 26B-A4B on 16GB RAM.
GGUFs: https://t.co/wQgEocxUId
QAT Guide: https://t.co/Nsm1yeGEHx
🇮🇹 A threat actor is advertising an alleged dataset tied to https://t.co/y8y4T1wSCv, reportedly containing telecom customer records, device-registration information, and subscription-related account data associated with users in Italy.
According to the listing, the exposed data allegedly includes:
Approximately 563,000 records
Full names, dates of birth, and gender information
Fiscal codes and VAT-related identifiers
Email addresses and phone numbers
Residential and corporate address information
Username and password-hash related fields
Customer-account and membership-status metadata
Device-registration and connectivity records
Notification tokens and Wi-Fi-related identifiers
Contract and subscription information
Billing-cycle and payment-method details
Contract renewal and termination metadata
Failed-login-attempt and activity-tracking fields
Marketing preferences and privacy-consent records
The structure of the dataset suggests exposure from a telecom CRM and subscriber-management environment integrating customer onboarding, device ecosystems, connectivity services, media subscriptions, and account-management workflows.
Particularly notable in the listing are references to device registrations, notification tokens, Wi-Fi identifiers, subscription lifecycle tracking, and password-hash fields. Even when passwords are hashed, improperly secured or weak hashing implementations can still create elevated risk if threat actors attempt credential cracking or credential-stuffing operations against other services.
Telecom-sector datasets remain highly valuable within underground communities because they can support identity fraud, SIM-swapping operations, phishing campaigns, account takeovers, and broader social-engineering attacks. The combination of contact information, subscription metadata, device relationships, and billing records significantly increases the operational value of such datasets for cybercriminal actors.
If verified, the alleged exposure could present both privacy and operational security concerns for affected individuals and organizations.
#DDW #Intelligence #DarkWeb #WindTre
Today we're open-sourcing Bumblebee, a read-only scanner for macOS and Linux.
It checks developer machines for risky packages, extensions, and AI tool configs.
Connected to Computer, it can trigger deeper scans whenever a new supply-chain risk emerges.
https://t.co/FOaWnF1yQy
open sourcing Marlin-2B 🐟
a tiny VLM to extract structured information from videos
Marlin is finetuned for two questions devs want to ask in their videos: what is happening, and when?
Best open model in its weight class, competitive with Gemini-2.5-flash at only 2B params 🧵
Legba is now officially packaged and part of Kali Linux rolling! To celebrate, I'm releasing 1.3.0, with super fast SMB shares enumeration, a bunch of fixes, and a dedicated website for the documentation! 🎉
@SarikPoligraf@putino Magari fosse cosí. È solo il sintomo di una classe privilegiata dove il numero dei taxi è artificialmente ridotto tutto a protezione dei taxisti. Oltre le code abbiamo, credo, uno dei prezzi piú alti per i taxi.
Here's a cool trick for y'all looking to create new Nuclei templates for exploitable CVEs!
Using CVEmap you can get a list of CVEs with public proofs of concept, that have been marked as exploitable by CISA, are remotely exploitable AND don't have a Nuclei template (yet)!
Flags:
-k / -kev: Marked as exploitable vulnerabilities by CISA
-t=false / -template=false: Has no public Nuclei templates
-poc: Has public published POC
-re / -remote: is remotely exploitable
Good luck! 🤞
#nuclei #hacking #pentesting #bugbounty #CVEmap
We're open-sourcing Cua Driver - our new macOS driver that lets any agent (Claude Code, Codex, your own loop) drive any app in the background, with true multi-player and multi-cursor built-in.
1/8
🗞️ipadecrypt just dropped — an open-source tool that lets you download and decrypt iOS apps by bundle ID📦
https://t.co/zJJBtqrQk3
No need to run the app. Uses a clever FairPlay trick to get plaintext straight from memory.
Works even with iOS 26 apps 👀