Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

2026-07-03T07:23:26Z22a89a8430ef1ff4f4050f790b211412dcf8fdc90ef9dc7408626f4aab126488
CISAChocoPoCCisco Unified CMClickFixConsentFixDHSFortiBleedHSIN breachINCKubota intrusionLynxMFA bypassMicrosoft 365OAuthOpera Paste ProtectRATScattered SpiderSharePoint RCEShinyHuntersUnified Communications Managercredential theftdata breachextraditionransomwaretrojanized PoC

What happened

Multiple high-risk incidents and active exploitations were reported across enterprise and government environments. Key stories: novel OAuth-based MFA bypass techniques dubbed ConsentFix and ClickFix are rapidly stealing Microsoft 365 tokens via fake prompts and social-engineered OAuth flows; CISA warns of active exploitation of a high-severity Microsoft SharePoint RCE patched in May; Cisco confirmed active exploitation of a recently patched Unified Communications Manager (Unified CM) flaw; the FortiBleed credential-theft campaign has been linked to INC/Lynx ransomware actors, suggesting stolen

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
22a89a8430ef1ff4f4050f790b211412dcf8fdc90ef9dc7408626f4aab126488
Enrichment time
2026-07-03T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.