Daily Recap, U.S. export controls compelled Anthropic to take Fable 5 and Mythos 5 offline for foreign nationals, underscoring tighter access to advanced AI models. Elsewhere, Chinese-linked actors showed long-running stealth in an authentication hijack and Linux backdoor campaigns, while Arch Linux AUR package hijacking pushed an infostealer and eBPF rootkit. #Anthropic #Fable5 #Mythos5 #Fable5 #Mythos5 #AuthHijack #LinuxBackdoor #ArchLinuxAUR #eBPF #Conti #ShinyHunters #OraclePeopleSoft #Coupang #23andMe #phpBB #FISA #DeepfakePornSite
AI Export Controls
- U.S. export restrictions forced Anthropic to take Fable 5 and Mythos 5 offline for foreign nationals, highlighting tightening controls on advanced AI access β Fable 5, Mythos 5, AI Ban
China-Linked Threats
- Chinese hackers hijacked an authentication flow to spy on an isolated network for nearly a decade, showing long-term stealth and persistence β Auth Hijack
- A China-based cybercrime network was dismantled by the FBI after causing about $1.9B in losses, while Google separately sued a Chinese smishing group accused of abusing Gemini AI for phishing β FBI Takedown, Gemini Smishing
- China-linked attackers backdoored Linux login software to remain hidden for nearly a decade, underscoring the durability of long-running supply-chain compromise β Linux Backdoor
Linux Supply Chain
- More than 400 Arch Linux AUR packages were hijacked to deploy an infostealer and eBPF rootkit, with a related wave also pushing a Rust credential stealer β AUR Hijack, AUR Malware, Rust Stealer
Ransomware & Extortion
- A Ukrainian national pleaded guilty for involvement in the Conti ransomware operation and faces up to 20 years in prison β Conti Guilty, Conti Plea
- ShinyHunters is actively extorting universities after exploiting an unpatched Oracle PeopleSoft flaw, extending its campaign against higher education β Oracle Extortion
Data Breaches & Fines
- South Korea fined Coupang a record $409 million over a data breach, reinforcing the growing cost of large-scale privacy failures β Coupang Fine, More
- The bankruptcy administrator approved a $47 million settlement fund for 23andMe data breach victims, moving compensation forward for affected users β 23andMe Fund
- Maine disabled its data breach notification portal after fake disclosures, disrupting the stateβs incident-reporting process β Maine Portal
Web & App Security
- phpBB fixed an authentication bypass bug that had lurked for about a decade, closing a long-standing forum security gap β phpBB Fix
Law Enforcement & Surveillance
- A major U.S. surveillance program is poised to lapse after legislative deadlock, raising uncertainty around continued FISA authorities β Surveillance Lapse
- U.S., French, and Italian authorities shut down a massive deepfake porn site in a coordinated cross-border takedown β Deepfake Takedown