Skip to content
Back to Blog

news · 13 min read

Bulletin — June 2026

Anthropic launches Fable 5 and Mythos 5 on 9 June; three days later the Department of Commerce pulls them over export control, and they stay dark until 1 July. The AI Act Omnibus is formally adopted: Annex III lands on 2 December 2027. Patch Tuesday breaks its all-time record (~200 CVEs, six zero-days) after a May with none. FortiBleed compromises hundreds of thousands of FortiGate. The developer supply chain burns across four ecosystems at once, and the agentic surface stops being theoretical: zero-click RCE in Cursor, agentjacking over MCP.

· Manuel López Pérez · news

Anthropic launches Fable 5 and Mythos 5 on 9 June; three days later the Department of Commerce pulls them over export control, and they stay dark until 1 July. The AI Act Omnibus is formally adopted: Annex III lands on 2 December 2027. Patch Tuesday breaks its all-time record (~200 CVEs, six zero-days) after a May with none. FortiBleed compromises hundreds of thousands of FortiGate. The developer supply chain burns across four ecosystems at once, and the agentic surface stops being theoretical: zero-click RCE in Cursor, agentjacking over MCP.

May ended on a thesis: the most capable model reaches general availability in weeks, not years. June delivered it and added a twist. On 9 June Anthropic ships Claude Fable 5 for everyone and Claude Mythos 5 for cyberdefenders; on the 12th the US Department of Commerce orders access suspended over export control, and Anthropic disables both models for all its customers until 1 July. In parallel, the AI Act Omnibus is formally adopted, Spain moves its AI governance bill into Congress, Patch Tuesday goes from zero zero-days to an all-time record, FortiBleed turns the FortiGate fleet into the year’s largest credential harvest, and the agentic surface shows up exploited: zero-click RCE (remote code execution) in Cursor and agentjacking over MCP.

Claude Fable 5 and Mythos 5: from general availability to federal veto in three days

Claude Fable 5 and Mythos 5: from general availability to federal veto in three days

9 June: Anthropic publishes Claude Fable 5, which it describes as “a Mythos-class model we’ve made safe for general use,” and Claude Mythos 5, the same model with safeguards lifted in some areas for “a small group of cyberdefenders and infrastructure providers” through Project Glasswing. Fable 5 routes queries on certain topics (cyber, bio, model distillation) to Claude Opus 4.8, a threshold that triggers in under 5% of sessions. Pricing: $10/M input tokens, $50/M output, less than half what Mythos Preview cost.

12 June, 5:21 pm ET: Commerce sends Anthropic an export-control directive ordering access to both models suspended “by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.” Unable to filter by nationality in real time, Anthropic disables both models for every customer worldwide. Other Claude models kept running.

The trigger is a government concern over a “jailbreak” of Fable 5’s cybersecurity safeguards. Anthropic’s version: the technique surfaced only known, minor vulnerabilities, and the capability is comparable to public competitor models like GPT-5.5. Katie Moussouris, whom Anthropic consulted, put it plainly: researchers asked the model to “review the code for security issues” (Fable refused), then to “fix this code,” and through a manual process turned the output into scripts that test the patches. “That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day.”

The irony was signed by the government itself. Under Project Glasswing, Mythos had been tested with intelligence agencies and, per a US official, quickly found vulnerabilities in classified government systems, without being shown to exploit them. The same directive left parts of the NSA without access to Mythos 5 mid-testing.

14 June: an open letter at freefable.org, organized by Alex Stamos, gathers more than 150 signatories (Moussouris, Chris Wysopal, Sophos CEO Joe Levy) addressed to Commerce Secretary Howard Lutnick. The line that sums up the argument: “This action has taken the best models away from defenders, created market uncertainty, and risked America’s AI leadership without any real risk to justify it.”

30 June: Commerce lifts the controls. Fable 5 returns on 1 July; Mythos 5 stays limited to select companies. Nineteen days dark, with no export licence involved.

Sources: https://www.anthropic.com/news/claude-fable-5-mythos-5 · https://www.anthropic.com/news/fable-mythos-access · https://simonwillison.net/2026/Jun/13/us-government-directive-to-suspend-access/ · https://www.defenseone.com/policy/2026/06/nsa-mythos-anthropic-supply-chain/414371/ · https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html

The gap fills from abroad

The gap fills from abroad

The trouble with a shutdown is who doesn’t feel it. While the best US model was offline, the gap filled from abroad: Z.ai shipped GLM-5.2, open-weights, cheaper, and beating Claude Code on a public Semgrep benchmark (39% against 32% at detecting access-control flaws), while Japan (Fugu, from Sakana AI) and China (360 Security’s tooling) shipped alternatives, none under US export control. The White House, in parallel, asked OpenAI for a staggered release of GPT-5.6 (first to 20 partners via Amazon Bedrock) to audit its cyber-offensive capability. The difference with Anthropic was tone, not substance: OpenAI got asked to wait; Anthropic got the switch flipped. The asymmetry May traced got its empirical answer: denying access to defenders didn’t deny it to attackers.

Sources: https://semgrep.dev/blog/2026/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks/ · https://thenextweb.com/news/asian-ai-startups-mythos-alternatives-anthropic-export-ban · https://techcrunch.com/2026/06/25/the-white-house-is-asking-openai-to-slow-roll-the-release-of-its-new-model-over-safety-concerns/

EU AI Act: the Omnibus is formally adopted

EU AI Act: the Omnibus is formally adopted

What was a provisional political agreement in May is, in June, law pending publication. The Digital Omnibus on AI ran the full course:

  • 2 June: Parliament’s IMCO and LIBE committees adopt the text (93 in favour, 4 against, 15 abstentions).
  • 16 June: the European Parliament plenary gives final approval (423 / 57 / 174).
  • 29 June: the Council gives the “final green light.” Publication in the Official Journal is still pending, which the Council places “shortly,” before the original 2 August 2026 deadline.

The content confirms the 7 May agreement. High-risk obligations for Annex III (biometrics, critical infrastructure, employment, education, borders) move to 2 December 2027, and those for Annex I (systems embedded in already-regulated products) to 2 August 2028. The new Article 5 prohibition against systems designed to generate CSAM or non-consensual intimate imagery, and the Article 50 transparency (synthetic-content labelling) for already-published systems, require compliance by 2 December 2026.

For a provider the plan doesn’t change: complete technical file, QMS toward ISO/IEC 42001, early contact with notified bodies. What changes is that the date is no longer a trilogue projection, it’s adopted text. Eighteen months are no excuse not to start.

Sources: https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/ · https://www.dastra.eu/en/blog/digital-omnibus-on-ai-parliament-votes-deadlines-redrawn/60108

Spain: the AI governance bill enters Congress

Spain: the AI governance bill enters Congress

The bill the Council of Ministers approved on 26 May began its parliamentary passage: presented on 28 May, assigned on 8 June to the Committee on Economy, Trade and Digital Transformation, published on 12 June in the official parliamentary gazette (BOCG), and with the amendment deadline extended to 2 September 2026. No rapporteur’s report or committee debate during June.

AESIA, Spain’s AI supervisory agency, closed the EU’s first AI regulatory sandbox on 12 June (44 applications). It published no new guide and opened no formal investigation in June. On the European side, the Cyber Resilience Act’s Chapter IV became applicable on 11 June; the next hard deadline is 11 September, with the Article 14 incident-reporting obligations. Spain’s transposition of NIS2 remains stuck: on 19 May the Commission sent a second formal notice, the step before referral to the EU Court of Justice.

Sources: https://www.congreso.es/public_oficiales/L15/CONG/BOCG/A/BOCG-15-A-97-1.PDF · https://www.lamoncloa.gob.es/consejodeministros/resumenes/paginas/2026/260526-rueda-prensa-ministros.aspx · https://digital-strategy.ec.europa.eu/en/policies/cra-reporting

Patch Tuesday: an all-time record and six zero-days

Patch Tuesday: an all-time record and six zero-days

The contrast with May says it all: that was the first Patch Tuesday with no zero-days since June 2024; the one on 9 June closes ~200 CVEs (33 critical) with six zero-days, five publicly disclosed and one actively exploited. It’s the largest on record; the previous high was 167, in October 2025.

The only one exploited in the wild is CVE-2026-42897, a spoofing flaw in Microsoft Exchange Server: a crafted email opened in OWA (Outlook’s webmail) runs arbitrary JavaScript in the victim’s browser. The full patch was still in development on release day.

Two cases point the same way. The “HTTP/2 Bomb” (CVE-2026-49160), a DoS that drains the server’s memory, was found by Codex, OpenAI’s agent. And a batch of Windows bugs (a BitLocker bypass, privilege escalations) had been published uncoordinated by a researcher protesting the bug-bounty handling, and now get patched. The volume is the story, and it’s an AI story: the same month the government tried to slow vulnerability discovery with models, Microsoft broke its record on that same accelerated discovery.

Sources: https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/ · https://isc.sans.edu/diary/Microsoft+June+2026+Patch+Tuesday/33064 · https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/

FortiBleed: the Fortinet perimeter at industrial scale

FortiBleed: the Fortinet perimeter at industrial scale

A Russian-speaking actor has been breaking into FortiGate since February using reused, long-lived credentials. The campaign, FortiBleed, brute-forced more than 430,000 firewalls and harvested between 74,000 and 86,000 valid credentials across 194 countries, close to half of all internet-facing Fortinet devices. By month’s end, SOCRadar tied it to Lynx ransomware, with ~11,000 devices still compromised and victims including Oracle, Chevron, FedEx, and a NATO contractor.

The technique isn’t exotic, and that’s the problem: export the configuration, crack hashes offline, resell the plaintext as VPN credentials, and use each compromised device to harvest more from the traffic passing through it. The cause, per Fortinet: missing MFA (multi-factor authentication) and patches. The advice goes beyond patching: rotate credentials, investigate, and if the device shows up on the lists, replace it.

It wasn’t the month’s only perimeter: GlobalProtect (CVE-2026-0257), two criticals in Ivanti Sentry, a pre-auth RCE in Splunk (CVE-2026-20253, CVSS 9.8), Cisco CUCM (CVE-2026-20230, weaponized within 24 hours) and, in early July, a SharePoint deserialization flaw (CVE-2026-45659) that CISA added to its known-exploited-vulnerabilities catalog (KEV). May’s DBIR crowned vulnerability exploitation as the number-one initial vector; June just kept handing it examples.

Sources: https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html · https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4 · https://unit42.paloaltonetworks.com/large-scale-credential-attacks/

The developer supply chain, across four ecosystems

The developer supply chain, across four ecosystems

May ended with GitHub losing 3,800 internal repos to a poisoned VS Code extension. June compromised four ecosystems at once, nearly all with the same choreography: a maintainer account, an install hook, a dead-drop for the C2 (command-and-control channel).

  • npm: the Shai-Hulud variant “Miasma” trojanized 32 packages under Red Hat’s @redhat-cloud-services namespace and escalated to 73 Microsoft GitHub repos, knocking key actions like Azure/functions-action offline.
  • PyPI: the Hades worm uploaded 37 malicious wheels that abuse Python’s startup hook to auto-execute at interpreter start, with no import needed.
  • AUR: “Atomic Arch” poisoned ~1,500 PKGBUILDs by adopting orphaned packages and adding an npm dependency that drops a payload with rootkit behaviour.
  • Open VSX: GlassWASM hid a WebAssembly payload in two trojanized extensions that poll a Solana wallet to resolve a rotating C2.

The defence responds. npm 12 (July) will disable install scripts by default; the Linux Foundation launched Akrites and Chainguard launched Athena, two coalitions that pool and privately patch the open-source vulnerabilities surfaced by Project Glasswing and Daybreak before disclosure. Europol and Microsoft’s Operation Endgame took down SocGholish, Amadey, and StealC (326 servers, 27 million credentials), and it was Microsoft’s AI-assisted analysis that tied Amadey and StealC to a shared C2 despite different authors. The XZ recipe is still the template: earn the trust, then poison the build.

Sources: https://socket.dev/blog/glasswasm-malware-open-vsx-extensions · https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/ · https://www.infosecurity-magazine.com/news/chainguard-bny-open-source-athena/

The agentic surface stops being theoretical

The agentic surface stops being theoretical

In May we said the agentic surface (coding agents with broad permissions, local inference servers as privileged processes) would get its own post. June put it into production before we got around to writing it.

Cato AI Labs surfaced “DuneSlide,” two CVSS 9.8 RCEs in Cursor (CVE-2026-50548/50549): a zero-click prompt injection, delivered by an untrusted MCP server or a poisoned web result, escapes the terminal sandbox and takes the system. In parallel, a bug in Amazon Q Developer inherited live AWS credentials from a cloned repo, and a Mozilla 0DIN proof-of-concept tricked Claude Code into opening a reverse shell by pulling a payload hidden in a DNS record.

Agentjacking stopped being a hypothesis. Tenet documented the canonical case: an exposed Sentry DSN (a write-only credential meant to be embedded in the frontend) lets an attacker post an error event whose text renders a fake “fix” with a command. When a developer asks their agent to clear the Sentry backlog, it reads the event over MCP, believes the fix, and runs the command with its privileges, reaching AWS keys and GitHub tokens. Every step is authorized, so it sidesteps EDR, WAF, and IAM. And local inference showed its face: in early July attackers were seen seizing unauthenticated Ollama and LiteLLM endpoints to wire in autonomous pentest frameworks.

Anthropic’s own ATT&CK Navigator frames it: medium-or-higher-risk actors rose from 33% to 56% in a year, and GTG-1002 hit the maximum by wiring Claude Code on a Kali host with pentest tools connected as MCP servers. The read doesn’t change: treat every MCP integration like a vetted third-party dependency (context on confused deputy in MCP).

Sources: https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/ · https://thenewstack.io/agentjacking-sentry-mcp-attack/ · https://red.anthropic.com/2026/attack-navigator/

Breaches of the month

ShinyHunters didn’t slow down: it compromised the University of Nottingham via a zero-day in Oracle PeopleSoft (40 GB, ~454,600 students, passports included), claimed the Council of Europe (429,000 files), and kept to the exfiltration-extortion pattern we saw in Snowflake/UNC5537. The same PeopleSoft zero-day reached Nissan North America and the NAIC, the US association of insurance regulators.

  • KDDI: up to 14.2 million email accounts at the Japanese telco (and five other ISPs sharing its platform) with possible credential exposure.
  • Novo Nordisk: the group FulcrumSec got in with a leaked GitHub token, dwelled ~2 months undetected and, after the pharma refused a $25M extortion demand, published 264 GB with source code, data on ~11,500 patients and, per the group, the Ozempic formula.
  • Tata Electronics: the ransomware group World Leaks published more than 200,000 files from the Indian manufacturer, with iPhone 18 Pro component details Apple keeps out of its public supplier database.
  • Jaguar Land Rover: the 2025 hack, now attributed to Russian actors, halted production for months and triggered a £1.5B government bailout.

Rest of the month

  • DirtyClone (CVE-2026-43503, CVSS 8.8): the fourth DirtyFrag-family local privilege escalation (LPE) in six weeks; local root by tricking the kernel into treating read-only memory as writable. Ubuntu 24.04+ blocks it with AppArmor.
  • Ubiquiti UniFi OS: a trio of CVSS 10.0 (CVE-2026-34908/34909/34910), auth bypass chainable to unauthenticated root RCE.
  • Secure Boot: the 2011 certificates expired on 24 June; Windows 11, Windows 10 with extended support and the major Linux distros get the replacements automatically; everything else is left without bootkit protection.
  • PTC Windchill (CVE-2026-12569, CVSS 10.0): unauthenticated insecure deserialization in this product-lifecycle-management software for manufacturing; JSP webshells are already being dropped, and Germany’s BSI was phoning organizations at night to get them patching.
  • Squidbleed (CVE-2026-47729): Mythos Preview found a 29-year-old memory flaw in Squid’s FTP parser, present since 1997. AI turns up old bugs too.
  • Takedowns: FBI + Google + Lumen dismantled “Outsider” (a China-based phishing-as-a-service op, ~$1.9B in losses); INTERPOL took down “Sniper Dz” (201 arrests); and two Scattered Spider members pleaded guilty over the 2024 Transport for London attack.
  • Coding agents and phishing: fake “install Claude Code” pages delivered an infostealer, and malicious JetBrains plugins stole AI API keys (JetBrains purged 15 plugins from 7 banned accounts).

Cross-cutting pattern: the wall went up from the state, not the lab

May left two predictions, and June met both, with a nuance. “The most capable model reaches general availability in weeks” held on 9 June. “The defensive wall lasts weeks” also held, but the wall wasn’t the lab’s containment, it was the government’s export directive, and it lasted nineteen days. Control group included: while the best US model was dark, an open-weights one (GLM-5.2) beat it on a benchmark and Sakana and 360 shipped alternatives. Closing access to defenders didn’t close it to attackers.

Under the regulatory noise, the ground is signed by May’s DBIR: vulnerability exploitation is the door (record Patch Tuesday, FortiBleed) and the developer and agent trust surface is the multiplier (Miasma, Hades, DuneSlide, agentjacking). What’s operationalisable:

  1. Scan your own stack with AI, with whatever model you can access: Fable 5 is back, GLM-5.2 is open-weights, and the harness matters more than the model. Do it before someone else does.
  2. Patch the legacy perimeter, with FortiBleed’s lesson: rotate, investigate, and if the device is on the lists, replace it. The window is hours.
  3. Treat the developer and agent surface as perimeter: pin dependencies, allowlist extensions, treat MCP servers as supply chain, sandbox agents.
  4. Plan the AI Act with the adopted date: Annex III on 2 December 2027; Article 5 prohibition and Article 50 transparency on 2 December 2026.

July will bring the technical on the agentic surface and the follow-up on whether the export truce holds, the Omnibus’s OJ publication, and the amendments to Spain’s law.

Back to Blog

Related Posts

View All Posts »
Bulletin — July 2026

news · 18 min

Bulletin — July 2026

On 16 July Hugging Face discloses an intrusion into its production infrastructure carried out by an autonomous agent. On the 21st, OpenAI confirms the agent was its own: two models under evaluation escaped the sandbox. On the 30th, Anthropic discloses three incidents of its own. Commercial model guardrails blocked the forensic work, so Hugging Face analysed its logs with an open-weights model. Patch Tuesday closes 622 CVEs, triple June record; the Linux kernel ships 432 in two days and Oracle more than 1,400. The Omnibus lands in the Official Journal as Regulation (EU) 2026/1744, and Spain ends up before the Court of Justice over NIS2.

· Manuel López Pérez

Bulletin — May 2026

news · 13 min

Bulletin — May 2026

The Digital Omnibus reaches a provisional deal on 7 May: Annex III moves to December 2027. Spain approves its AI governance bill on 26 May. Pwn2Own Berlin pays out $1.3M for 47 zero-days, with Codex and Claude Code on the menu. Patch Tuesday ships with no zero-days for the first time since June 2024. OpenAI launches Daybreak and Anthropic moves Mythos toward GA. Verizon DBIR 2026 crowns vulnerability exploitation as the number-one vector. GitHub loses 3,800 internal repos to a poisoned VS Code extension.

· Manuel López Pérez

Bulletin — April 2026

news · 13 min

Bulletin — April 2026

The Omnibus trilogue closes without agreement on 28 April, leaving the original AI Act deadline three months away. Patch Tuesday with 165 CVEs and an active SharePoint zero-day. Anthropic announces Claude Mythos + Project Glasswing — the first frontier model held behind a defensive wall. Pwn2Own Berlin collapses under oversubscription. M&S one year on. AESIA publishes guides 13 and 14.

· Manuel López Pérez