Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
2026-07-03T07:23:26Z•22a89a8430ef1ff4f4050f790b211412dcf8fdc90ef9dc7408626f4aab126488
CISAChocoPoCCisco Unified CMClickFixConsentFixDHSFortiBleedHSIN breachINCKubota intrusionLynxMFA bypassMicrosoft 365OAuthOpera Paste ProtectRATScattered SpiderSharePoint RCEShinyHuntersUnified Communications Managercredential theftdata breachextraditionransomwaretrojanized PoC
What happened
Multiple high-risk incidents and active exploitations were reported across enterprise and government environments. Key stories: novel OAuth-based MFA bypass techniques dubbed ConsentFix and ClickFix are rapidly stealing Microsoft 365 tokens via fake prompts and social-engineered OAuth flows; CISA warns of active exploitation of a high-severity Microsoft SharePoint RCE patched in May; Cisco confirmed active exploitation of a recently patched Unified Communications Manager (Unified CM) flaw; the FortiBleed credential-theft campaign has been linked to INC/Lynx ransomware actors, suggesting stolen
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 22a89a8430ef1ff4f4050f790b211412dcf8fdc90ef9dc7408626f4aab126488
- Enrichment time
- 2026-07-03T07:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.