Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
2026-07-03T13:23:30Z•8c5faf400bae24e68a2b396ca96f759819184b9891c1f3ba5609feeb5aa963fb
CISAChocoPoCCisco Unified CMClickFixConsentFixFortiBleedHSIN breachKubotaLynx ransomwareMFA bypassMedtronicMicrosoft SharePointOAuthOpera Paste ProtectShinyHuntersactive exploitationcredential theftcyber espionagedata breachincident responsetrojanized PoC
What happened
Multiple high-impact security incidents and active exploitation events were reported: CISA warned of active exploitation of a recently patched Microsoft SharePoint RCE; Cisco confirmed attackers are exploiting a patched Unified Communications Manager flaw; the FortiBleed credential-theft campaign has been linked to INC/Lynx ransomware operators; and DHS confirmed a breach of the HSIN information-sharing platform. New attack techniques (ConsentFix and ClickFix) rapidly hijack Microsoft 365 accounts via OAuth/MFA bypass prompts, and Opera introduced a Paste Protect feature to mitigate ClickFix._
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8c5faf400bae24e68a2b396ca96f759819184b9891c1f3ba5609feeb5aa963fb
- Enrichment time
- 2026-07-03T13:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.