Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

2026-07-03T13:23:30Z8c5faf400bae24e68a2b396ca96f759819184b9891c1f3ba5609feeb5aa963fb
CISAChocoPoCCisco Unified CMClickFixConsentFixFortiBleedHSIN breachKubotaLynx ransomwareMFA bypassMedtronicMicrosoft SharePointOAuthOpera Paste ProtectShinyHuntersactive exploitationcredential theftcyber espionagedata breachincident responsetrojanized PoC

What happened

Multiple high-impact security incidents and active exploitation events were reported: CISA warned of active exploitation of a recently patched Microsoft SharePoint RCE; Cisco confirmed attackers are exploiting a patched Unified Communications Manager flaw; the FortiBleed credential-theft campaign has been linked to INC/Lynx ransomware operators; and DHS confirmed a breach of the HSIN information-sharing platform. New attack techniques (ConsentFix and ClickFix) rapidly hijack Microsoft 365 accounts via OAuth/MFA bypass prompts, and Opera introduced a Paste Protect feature to mitigate ClickFix._

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8c5faf400bae24e68a2b396ca96f759819184b9891c1f3ba5609feeb5aa963fb
Enrichment time
2026-07-03T13:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says · Baitaphish