Aristotelis Tzafalias

146 Followers
496 Following
2.3K Posts
When buffers overflow into policy

One **possible** scenario: How a narrow security concern became a worldwide shutdown of Fable 5 and Mythos 5 (June 12–13, 2026).

1. The trigger.

The US government believes it found a jailbreak in Fable 5 — asking the model to read a codebase and find or fix flaws, yielding cyber uplift. Citing "national security authorities," it issued an export-control directive to Anthropic at 5:21pm ET on June 12.

2. How an export control reaches users inside the US (this is the likely mechanism — the actual directive is non-public).

Model weights are treated as controlled "technology" (a 4E091-type control). Under the "deemed export" doctrine (EAR sections 734.13 and 734.15), giving a foreign national access counts as an export to their home country, even if they never leave the US. The directive's scope: suspend all access by any foreign national, inside or outside the US, including foreign-national employees.

3. Compliance and result.

Anthropic says complying with the foreign-national restriction requires disabling the models for every customer. (Why nationality-based filtering wasn't viable is inferred from reporting, not an Anthropic quote.)

4. The result.

Fable 5 and Mythos 5 are shut down worldwide for everyone, US and non-US alike. US users lose access through the mechanics of compliance, not the directive's terms. Other Claude models, such as Opus 4.8, stay online; the claude-fable-5 API string now returns an error.

Sources: Anthropic (anthropic.com/news/fable-mythos-access), CNBC, NBC News, Axios. The legal mechanism shown is analysis — the directive itself hasn't been published.

#AI #ExportControls #Anthropic

When I struggle to structure my thoughts about what's happening I turn to writing. Today about the recent US Anthropic ban news, what it says about power and dependency, and what it should mean for Europeans and citizens of the world. It's a long one. https://lucumr.pocoo.org/2026/6/13/americans-only/
Dangerous Technology For Americans Only

AI nationalism, safety and European weakness.

Armin Ronacher's Thoughts and Writings

Quantum key distribution research report
Published - 10 June 2026

"This is independent research commissioned by the (UK) Department for Science, Innovation and Technology (DSIT), and the views expressed do not represent HM Government policy."

https://www.gov.uk/government/publications/quantum-key-distribution-research-report/quantum-key-distribution-research-report

See also: Quantum networking technologies - A white paper outlining the UK NCSC’s approach to quantum security technologies. 5 August 2025

https://www.ncsc.gov.uk/paper/quantum-networking-technologies

Quantum key distribution research report

GOV.UK

Patch Tuesday, Exploit Tuesday
Benchmarking n-day exploit generation.

Author: Josh Merrill - June 8, 2026

"This is not a new debate. Metasploit caught it. Cobalt Strike caught it. Every offsec tool of consequence in the last twenty years has eaten the same wave of “should we even release this.” The empirical answer has been the same each time. Malicious actors are not waiting for a moral debate inside the security industry, they are pushing toward their objectives regardless. Withholding tools and capabilities from offensive security practitioners slows the rate of defensive adaptation, and the gap that opens gets filled by the bad actors anyway.

The same logic applies to LLM-driven exploit generation. Time-to-exploit numbers are going down. The benchmarks need to exist in public so the defensive community can see what is coming and ship the corresponding mitigations, detections, and policies. Anthropic’s own exploit-evals piece made the call: “The field needs more work like ExploitBench and ExploitGym, across more vulnerability classes, more targets, and more stages of the cyber attack chain.”

ndaybench is one attempt in that direction. The tedious work of moving each CVE from disclosure to a graded bench task is ongoing. Results when there is something worth showing."

https://magic-box.dev/blog/patch-tuesday/

josh merrill

Benchmarking n-day exploit generation.

RE: https://infosec.exchange/@aristot73/116741879062541352

lol. they're gonna fold in 0.02s if US Gov looks at them sideways in a potentially threatening manner.

RE: https://infosec.exchange/@aristot73/116729740506287698

file under "be careful what you wish for"

Amodei, 10 June 2026: "The government should have the power to block or deter deployment of the model if it is determined, in light of third-party assessment, to present unacceptable risks. This power must be scoped to the above four specific risks and there must be protective measures against political favoritism or arbitrary decisions."

Trump Abruptly Bans Foreigners Using Anthropic’s Top Models https://www.flyingpenguin.com/trump-abruptly-bans-foreigners-using-anthropics-top-models/
👆 @fj

🇨🇿🇪🇺 AISLE, which outperforms Mythos in many categories of the Berkley Agentic Vulnerability rankings, has a great blog post that shows that the harness is more important than the model for bug finding

"AI cybersecurity capabilities are broadly accessible with current models, including cheap open-weights alternatives. The priority for defenders is to start building now: the scaffolds, the pipelines, the maintainer relationships, the integration into development workflows”

https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier

RE: https://infosec.exchange/@ollie_whitehouse/116742213277013226

Subscribe! It's free, excellent and export control proof