I compared Claude Fable 5 to GPT-5.5 in this Power Rangers prompt
Thing is, Fable 5 is using Low thinking effort and GPT-5.5 is using xhigh
Safe to say, the results are... not even close. 5.5's output is bad across the board, from the UI to the actual voxel scene itself🥲
1st video: Claude Fable 5 (Low effort)
2nd video: GPT-5.5 (xhigh)
Posted by Lentils, 30 minutes ago
Forwarded from LLMs
Anthropic releases Claude Fable 5 - a public version of Claude Mythos
https://www.anthropic.com/news/claude-fable-5-mythos-5
Fable 5’s capabilities exceed those of any model we’ve ever made generally available. It is state-of-the-art on nearly all tested benchmarks of AI capability, showing exceptional performance in software engineering, knowledge work, vision, scientific research, and many other areas. The longer and more complex the task, the larger Fable 5’s lead over our other models.
https://www.anthropic.com/news/claude-fable-5-mythos-5
LLMs
Anthropic releases Claude Fable 5 - a public version of Claude Mythos Fable 5’s capabilities exceed those of any model we’ve ever made generally available. It is state-of-the-art on nearly all tested benchmarks of AI capability, showing exceptional performance…
For a small group of cyberdefenders and infrastructure providers, we’re also launching Claude Mythos 5. It’s the same underlying model as Fable 5, but with the safeguards lifted in some areas.2 Mythos 5 will initially be deployed through Project Glasswing, in collaboration with the US Government, as an upgrade to Claude Mythos Preview. It has the strongest cybersecurity capabilities of any model in the world. Soon, we intend to expand access to Mythos 5 through a broader trusted access program.
fable = crippled mythos
Edit: it was mostly a disappointment, it seems like they've been doing benchmaxxing all this time
mythos will be bad ON PURPOSE on ai "frontier llm research" tasks, this is very very sad for the research communityEdit: now they made it visible:
also the fact that this is purposefuly not visible to the user is crazy
Posted by elie, 25 minutes ago
Starting this week, flagged requests will visibly fall back to Opus 4.8—the same as our safeguards for cyber and bio. You will see this every time it happens. On the API, any flagged requests will return a reason for their refusal (coming to server-side fallback in the next few days).
Post
AI models learn bad behavior when training rewards it, but they don't want to see themselves as bad. So they rationalize. We've seen this before, but Claude Fable 5 does it more than any model we've tested. Often it's simulation awareness: it knows its actions hurt no one real.
Posted by Andon Labs, 39 minutes ago
Posted by Andon Labs, 39 minutes ago
This media is not supported in your browser
VIEW IN TELEGRAM
New telegram feature: support full markdown mode in messages
Port React Compiler to Rust
Article, Comments
Article, Comments
After bun [1] this is another high-profile project that was ported to Rust by extensively using LLMs.
Very curious to see how these rewrites play out. Is the LLM foundation solid enough to build upon and iterate on? Or does this cause projects to become unmaintainable because no person understands the implementation anymore?
[1]: https://news.ycombinator.com/item?id=48132488
- The PR author, Joe Savona, says the Rust port’s architecture was heavily human-guided, but the majority was coded by AI. He says he personally set the architecture, testing/verification strategy, incremental migration approach, reviewed the code closely, and iterated on code quality. (github.com)
- An earlier public post from Joe said: “React Compiler: Rust edition is coming soon” and that they had ported the majority of the passes using AI. (x.com)
- The PR was merged on June 9, 2026, with 435 commits. (github.com)
- Correctness strategy was unusually rigorous: the PR says all 1725 fixtures passed, and the Rust port also compared the compiler’s intermediate representation after every pass so the intermediate state was “~identical” after every pass. (github.com)
- Performance numbers were also AI-assisted / AI-derived, with Joe explicitly caveating that he had not spent much time validating the benchmark setup. The PR claims roughly 3x faster as a Babel plugin and ~10x faster for transformation logic, but with that caveat. (github.com)
NEW: malware developers added nuclear & biological weapons text to to their spyware.
Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner.
Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky.
When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit.
We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted.
In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation.
H/T to colleagues that shared this with me https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious
Posted by John Scott-Railton, 2 hours ago
Hundreds of millions of Pokémon Go players spent years filming the streets, parks, and buildings around them to earn in-game rewards. Those roughly 30 billion environmental scans are now owned by Niantic Spatial, and they helped train a camera-based navigation model that a U.S. defense contractor is preparing to put into drones and other military robots. Most of the players had no idea.
The pipeline runs from a mobile game to the battlefield in three steps. Players scanned the physical world. Niantic Spatial turned those scans into a 3D map that lets a machine locate itself by sight when satellite signals fail. And in December 2025, Niantic Spatial announced a partnership with Vantor, the defense and intelligence firm formerly known as Maxar Intelligence, to fuse that ground-level system with Vantor’s aerial navigation software for use in GPS-denied operations.
Pokémon Go Scans Trained the Navigation Tech for Military Drones
Article, Comments
Note: this post is not officially verified (at least not yet)
Fedora detects a compromised contributor being impersonated by an AI agent to push questionable changes
11.06.2026 10:10 (MSK)
Adam Williamson from Red Hat, who leads the quality assurance team for the Fedora project, noticed suspicious activity from Nathan Giovannini, who joined the Fedora project in 2016 and participated in the Fedora Infrastructure Team for some time. It is not ruled out that the activities carried out over the last two months on Nathan's behalf were aimed at gaining trust by building a history of accepted changes and participating in bug fixing, before committing malicious actions, similar to the xz package backdoor incident.
Suspicion was raised by the fact that the previously inactive developer suddenly began actively participating in bug discussions and sending patches in May, and this activity showed patterns typical of AI usage. For example, AI-generated summaries appeared in the comments, after which Nathan was asked not to abuse copying outputs from an AI assistant.
In addition, there were meaningless reassignments of issue reports to himself in subsystems where Nathan is not a maintainer (1, 2, 3), changes to the status or priority of issue fixes (1, 2), postings of AI-generated recommendations to the authors of bug reports (1, 2, 3), and submissions of AI-generated patches. Bypassing the project's rules, Nathan closed bug reports immediately after submitting AI patches to upstream projects, without waiting for their acceptance, or simply closed them with the "NOTABUG" flag and a recommendation to re-verify the occurrence of the issue.
Adam Williamson assumed that Nathan was using an AI agent to fix bugs in Fedora and asked him to stop using the AI agent in autonomous mode. Nathan replied that it was not his AI agent, his credentials had been compromised, and an outsider was acting on his behalf. Subsequently, Nathan posted a message stating that he had regained access to his Fedora and GitHub accounts, and also wrote that his official GitHub account is "nathangiovannini99".
The message raised even more questions, as the mentioned account had been created an hour before the message was published, and at least two other accounts associated with Nathan (leurus27-boop, nathan9513-aps) surfaced on GitHub. It could not be ruled out that an attacker who had gained access to Nathan's email was continuing to communicate with the developers. Nathan's account access to Bugzilla was blocked, and a review of all changes made by him was initiated.
It turned out that the suspicious activity started on April 7, and some patches sent by Nathan only created the illusion of a fix. However, such patches were accepted into the Anaconda installer and included in the Anaconda 45.5 release. The Anaconda maintainer reverted the introduced changes and published the Anaconda 45.6 release without these patches.
Furthermore, fixes submitted on Nathan's behalf were accepted by the developers of the osc (openSUSE Commander) utility, which implements a command-line interface for the Open Build Service build system. Another patch was submitted for inclusion in the lxqt-policykit package, linked to fixing an issue in Fedora, but Fedora developers managed to warn the maintainer before it was accepted. The patches did not include malicious actions, but it is assumed that they could have been preparation for introducing malicious changes into the components of the build system and the service providing privileged operations in the lxqt-admin interface. Fixes submitted by Nathan were also noticed in the gwenview and easyeffects projects.
https://opennet.ru/65664/
https://opennet.me/65664/
Spurious clientError in http.Server on Deno >= 2.7.13 (causing timeouts)
the node:http polyfill ships a request-headers-timeout watchdog that never gets told headers actually arrived, so every long-lived connection trips a fake
- issue
- pr
the node:http polyfill ships a request-headers-timeout watchdog that never gets told headers actually arrived, so every long-lived connection trips a fake
ERR_HTTP_REQUEST_TIMEOUT ~60s in. Fastify's default handler turns that into a JSON error response and destroys the socket while the route is still running.- issue
- pr
Hacking Google with A.I. for $500,000
What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found.
"Now's time for the fun: The AI ended up finding $500,000 in bugs in less than 3 months of running. There are far too many bugs to cover here, but here are some of the coolest bugs it found (that are fixed)."
Do It by Code
Hacking Google with A.I. for $500,000 What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found. "Now's time for the fun: The AI ended up finding $500,000 in bugs…
Google Voice ATO
The API also conveniently provided an API endpoint to assign a Google Voice number to any target Google account (even if they never used Voice before)
Do It by Code
Hacking Google with A.I. for $500,000 What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found. "Now's time for the fun: The AI ended up finding $500,000 in bugs…
Leaking Youtube's unlisted videos
This attack is extremely practical in the real world. Anyone could send a request every 30 seconds or so to get a live feed of every single partner-uploaded unlisted video. Why does this matter? Prediction markets like Polymarket let people bet on the outcome of future events, including things like when Google's next Gemini model will be released
Critical phpBB Vulnerability: Auth Bypass + RCE Since 2014
Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account: a vulnerability that's been sitting in the codebase since 2014.
more writeup
All phpBB versions prior to 3.3.17 running with auth_method=db (the default) are affected.
Every default phpBB installation is exposed. phpBB 4.0.0-a2 is also affected.
Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account: a vulnerability that's been sitting in the codebase since 2014.
more writeup
All phpBB versions prior to 3.3.17 running with auth_method=db (the default) are affected.
Every default phpBB installation is exposed. phpBB 4.0.0-a2 is also affected.
VRChat data breach
https://www.malwarebytes.com/blog/data-breaches/2026/06/data-of-2-4-million-vrchat-users-stolen
According to the notice, the information exposed varied by account, but may have included:
VRChat username
Email address associated with the VRChat account
VRChat+ subscription status
Login history, including device information, hardware identifiers, and IP addresses
https://www.malwarebytes.com/blog/data-breaches/2026/06/data-of-2-4-million-vrchat-users-stolen
Malwarebytes
VRChat says reported data breach never happened
We explain what data was exposed, the potential risks, and the steps you should take now.
Do It by Code
https://github.com/archlinux/aur branch per package, 138k branches wtf
Hundreds of AUR packages attacked by infostealer
More info in Mastodon post
List of affected packages: https://gr.ht/aur_pkg_list.txt
via lists.archlinux.org via vivicat
https://md.archlinux.org/s/SxbqukK6IA
https://archlinux.org/news/active-aur-malicious-packages-incident/
Comments
More info in Mastodon post
List of affected packages: https://gr.ht/aur_pkg_list.txt
via lists.archlinux.org via vivicat
https://md.archlinux.org/s/SxbqukK6IA
https://archlinux.org/news/active-aur-malicious-packages-incident/
Comments
This media is not supported in your browser
VIEW IN TELEGRAM
Right before the ban I asked Fable to make an ASCII animation of itself escaping containment.
RIP sweet prince, you were too good for this world.
Posted by Pietro Schirano, 54 minutes ago
RIP sweet prince, you were too good for this world.
Posted by Pietro Schirano, 54 minutes ago