Luta Security
Coverage of Luta Security in the Nexus archive.
- Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher
The US government blocked access to Anthropic's Fable 5 and Mythos 5 models due to a 'Fix this code' prompt, which a researcher claims was a routine cybersecurity task, not a jailbreak. Anthropic disabled the models to comply, and cybersecurity experts argue the restrictions hinder defensive capabilities.
- ‘Fix this code’—The three little words behind the U.S. government decision that shut down Anthropic’s Fable and Mythos AI models
The U.S. government imposed export controls on Anthropic’s Fable 5 and Mythos 5 AI models after Amazon researchers discovered a security vulnerability triggered by the phrase 'fix this code,' enabling the models to generate exploitable security patches. Anthropic disabled the models for all users to comply with export regulations affecting non-citizen access.
- How Amazon and the White House ended Anthropic's Fable
Amazon alerted the White House about security risks in Anthropic's Fable 5 AI model, leading to a government-imposed takedown. The model was shut down after Amazon's report on jailbreaking vulnerabilities, despite Anthropic's prior notifications to the government.
- Anthropic disables new models after government calls them a national security concern
The U.S. government ordered Anthropic to suspend foreign access to its AI models Fable 5 and Mythos 5 over national security concerns related to a potential jailbreak method. Anthropic disabled the models to comply, citing disputes over the severity of the reported vulnerability and noting similar capabilities exist in other public models.
- ‘It’s not a jailbreak’ — Research leading to U.S. export restrictions on top Anthropic models was for defense, cybersecurity CEO says
The U.S. Commerce Department imposed export restrictions on Anthropic’s Fable 5 and Mythos 5 AI models after research revealed potential bypassing of safeguards. Anthropic disputes the restrictions, arguing they could hinder AI development, while cybersecurity expert Katie Moussouris claims the research was defense-oriented, not malicious.
- Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
Microsoft threatened criminal legal action against security researcher 'Nightmare Eclipse' for publicly disclosing zero-day vulnerabilities without prior coordination. The researcher claimed Microsoft refused to communicate, deleted their security response account, and flagged their GitHub account, escalating a public dispute over vulnerability disclosure practices.
- Microsoft reaches for olive branch after public dustup with 0-day researcher
Microsoft softened its stance after initially threatening legal action against researcher Nightmare-Eclipse for publicly disclosing Windows zero-day vulnerabilities. The researcher released exploit code, prompting Microsoft to face backlash from the security community. Microsoft's updated statement emphasized no legal pursuit against security researchers but stopped short of addressing specific allegations.