Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

Anthropic brings Mythos to the masses with Claude Fable 5, its most powerful generally available model ever

Published

on

Anthropic today launched two new AI models — Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, Project Glasswing, which it announced two months ago.

The company says Fable 5, which is the version most users and developers will get starting today, exceeds every Claude model it has previously made generally available — featuring stronger performance across software engineering, knowledge work, vision, scientific research and long-running tasks.

It smashes the existing benchmarks and comes atop on nearly all of them, though the prior Claude Mythos Preview version of the model still takes the top spots on computer use and multidisciplinary reasoning (see benchmark chart below and here).

Claude Fable 5 and Mythos 5 benchmark comparison chart

Claude Fable 5 and Mythos 5 benchmark comparison chart. Credit: Anthropic

Advertisement

The new Claude Mythos 5, by contrast, is less restricted in its capabilities, but more restricted in its availability. It is an upgraded version of the prior, similarly capable but limited release Mythos Preview model. As such, it has certain safeguards lifted — but it’s only officially accessible to Anthropic-approved users, including Anthropic’s cybersecurity partners in its Project Glasswing effort, and select biology researchers.

The key difference is that the general purpose Fable 5 wraps the same underlying Mythos-class capability in new safeguards. Anthropic says requests involving certain high-risk areas — including cybersecurity, biology and chemistry, and model distillation — are automatically routed to Claude Opus 4.8, Anthropic’s previously flagship general model, instead, with users notified when that happens. That is not the case on Mythos 5.

The company says more than 95% of Fable 5 sessions run entirely on Fable 5’s own responses, with no fallback, and that internal and external red-teaming efforts found no “universal jailbreaks” after more than 1,000 hours of testing.

Anthropic says Fable 5 is available to the general public today through its website, apps, and API, but that Mythos 5 will initially only be made available to users who already have access to the older Claude Mythos Preview.

Advertisement
Screenshot of Claude Fable 5 and Mythos 5 API information

Screenshot of Claude Fable 5 and Mythos 5 API information on Anthropic’s website.

Pricing, access and a tricky rollout

Anthropic is pricing both Fable 5 and Mythos 5 at $10 per million input tokens and $50 per million output tokens. The company says that is less than half the price of Claude Mythos Preview, but still ranks as the most expensive of major AI models available globally.

Model

Input

Advertisement

Output

Total Cost

Source

MiMo-V2.5 Flash

Advertisement

$0.10

$0.30

$0.40

Xiaomi MiMo

Advertisement

deepseek-v4-flash

$0.14

$0.28

$0.42

Advertisement

DeepSeek

deepseek-v4-pro

$0.435

$0.87

Advertisement

$1.305

DeepSeek

MiniMax-M3

$0.30

Advertisement

$1.20

$1.50

MiniMax

Gemini 3.1 Flash-Lite

Advertisement

$0.25

$1.50

$1.75

Google

Advertisement

Qwen3.7-Plus

$0.40

$1.60

$2.00

Advertisement

Alibaba Cloud

MiMo-V2.5

$0.40

$2.00

Advertisement

$2.40

Xiaomi MiMo

Grok 4.3 (low context)

$1.25

Advertisement

$2.50

$3.75

xAI

GLM-5

Advertisement

$1.00

$3.20

$4.20

Z.ai

Advertisement

Kimi-K2.6

$0.95

$4.00

$4.95

Advertisement

Moonshot/Kimi

GLM-5.1

$1.40

$4.40

Advertisement

$5.80

Z.ai

Grok 4.3 (high context)

$2.50

Advertisement

$5.00

$7.50

xAI

Qwen3.7-Max

Advertisement

$2.50

$7.50

$10.00

Alibaba Cloud

Advertisement

Gemini 3.5 Flash

$1.50

$9.00

$10.50

Advertisement

Google

Gemini 3.1 Pro Preview (≤200K)

$2.00

$12.00

Advertisement

$14.00

Google

GPT-5.4

$2.50

Advertisement

$15.00

$17.50

OpenAI

Gemini 3.1 Pro Preview (>200K)

Advertisement

$4.00

$18.00

$22.00

Google

Advertisement

Claude Opus 4.8

$5.00

$25.00

$30.00

Advertisement

Anthropic

GPT-5.5

$5.00

$30.00

Advertisement

$35.00

OpenAI

Claude Fable 5 / Claude Mythos 5

$10.00

Advertisement

$50.00

$60.00

Anthropic

For developers, Fable 5 is available through the Claude API as claude-fable-5. Anthropic says Fable 5 is fully available today on the Claude API and on consumption-based Enterprise plans.

Advertisement

For subscription users, the rollout is more complicated. Anthropic says Fable 5 will be included on Pro, Max, Team and seat-based Enterprise plans at no extra cost from today through June 22.

On June 23, the company plans to remove Fable 5 from those plans, after which using it will require usage credits. Anthropic says it aims to restore Fable 5 as a standard part of subscription plans as quickly as possible.

The difference between Fable 5 and Mythos 5

Anthropic is not presenting Fable 5 and Mythos 5 as two separate models in the usual “small versus large” sense. Instead, they appear to share the same base capability level. The difference is access control — that is, how easily it will be for users to get their hands on the models, and the guardrails embedded in each.

As previously mentioned Fable 5 includes a new safeguard layer that detects certain high-risk requests — including cybersecurity, biology and chemistry, and attempts to distill the model’s capabilities into other systems — and routes those requests to Claude Opus 4.8.

Advertisement

Mythos 5 lifts some of those restrictions for trusted users working in approved domains.

In practical terms, Mythos 5 is more powerful for sensitive cyber and biology work because it can answer in areas where Fable 5 falls back.

For most ordinary enterprise and developer tasks, however, Anthropic says Fable 5 performs effectively the same as Mythos 5.

The launch also signals how Anthropic plans to bring frontier models with dangerous dual-use capabilities into the market: not by releasing all capabilities to everyone, and not by simply refusing risky questions, but by routing some requests to a less capable model while keeping the stronger model available for the majority of everyday work.

Advertisement

A major improvement in autonomous coding

For enterprise buyers, the most immediate use case is likely software engineering. Anthropic says Fable 5 can work unattended for longer and with more independence than previous Claude models, which is exactly the capability enterprises need if they want AI agents to do more than autocomplete code or answer developer questions.

On SWE-bench Pro, which measures a model’s ability to complete difficult software engineering tasks, Anthropic says Fable 5 and Mythos 5 reach 80.3%, vastly outperforming OpenAI’s latest and greatest general model GPT-5.5, which scored 58.6%.

On Cognition’s FrontierCode Diamond benchmark, which tests high-quality, maintainable agentic coding, the models score 29.3%, compared with 13.4% for Claude Opus 4.8 and 5.7% for GPT-5.5, according to the benchmark table included in Anthropic’s materials.

Anthropic also says Fable 5 scores highest among frontier models on FrontierCode even at medium reasoning effort, suggesting the model may deliver stronger coding results without always needing maximum compute.

Advertisement

The most striking customer example comes from Stripe. Anthropic says Stripe tested Fable 5 in a 50-million-line Ruby codebase and found that the model completed a codebase-wide migration in one day that otherwise would have taken a team more than two months by hand. Stripe said, “Fable 5 compresses months of engineering into days. In our 50-million-line Ruby codebase, it did in a day what would’ve taken us more than two months by hand.”

Other early users describe the model as especially useful for long-horizon development tasks. Cursor said, “Fable 5 is the state of the art model on CursorBench. It’s opened up a class of long-horizon problems that were out of reach for earlier models.” Replit said Fable 5 is the highest-performing model it has tested on ViBench, its end-to-end “vibe-coding” benchmark, and that it builds apps in less time with fewer tokens. Figma said Fable 5 is “a clear step forward on agentic coding and prototyping.”

This is the enterprise shift Anthropic is trying to sell: AI coding systems that can take on larger units of work, not just individual tickets. That could include codebase migrations, app prototyping, pull request review, test generation, debugging across unfamiliar tools, user interface design and multi-step internal software projects.

Base44 said, “Fable 5 is much deeper and better at one-shotting full apps, and its tool calling is excellent.” Genspark said, “Fable 5 came out #1 on our evals, winning head-to-head against every model we tested. It was significantly stronger on the hardest tasks in the set — UI design and game coding.” Rakuten said, “At the highest effort, Fable 5 reflects on and validates its own work. For us, that’s what makes highly autonomous operations possible — the extra thinking pays for itself.”

Advertisement

For CTOs and engineering leaders, that suggests the model’s value may come less from raw code generation and more from sustained execution: understanding an intent, planning steps, calling tools, checking its own work and continuing through a task without constant human steering.

Knowledge work, finance, legal and operations

Anthropic is also positioning Fable 5 as a stronger model for enterprise knowledge work. On GDPval-AA, Anthropic reports a score of 1932 for Fable 5 and Mythos 5, compared with 1890 for Claude Opus 4.8, 1769 for GPT-5.5 and 1314 for Gemini 3.1 Pro.

On GDPpdf, a benchmark focused on visual document reasoning, Fable 5 and Mythos 5 score 29.8% without tools, compared with 22.5% for Opus 4.8, 24.9% for GPT-5.5 and 16.7% for Gemini 3.1 Pro.

That matters for enterprises because much of corporate work still lives in messy documents: PDFs, spreadsheets, charts, reports, contracts, filings, slide decks and screenshots. Anthropic says Fable 5 shows gains in document-based reasoning, chart and table interpretation and complex problem solving.

Advertisement

Hex said, “Fable 5 is the first to break 90% on our core analytics benchmark of complex, long-running analytical tasks — a 10-point jump over Opus. On the hardest questions, it shows strong judgment and attention to nuance.” Hebbia said Fable 5 was the highest-scoring model on its Finance Benchmark for senior-level reasoning, with double-digit gains in document reasoning, chart and table interpretation, and problem solving.

The finance examples are notable because they point to AI agents moving beyond summarization into higher-stakes analytical workflows.

IMC said Fable 5 “aced our trading-analysis evaluations nearly across the board: factual lookup, conceptual reasoning, root-cause analysis, expected-value analysis.” Optiver said the model was stronger than Opus 4.8 on its trading benchmark and “remarkably consistent,” scoring identically across repeated runs. Balyasny Asset Management said Fable 5 was the strongest finance-first model it had tested.

Legal and operations teams may also see immediate impact. Crosby Legal said, “Fable 5 feels materially different. In blind review, our lawyers found its redlines matched or beat our current model every time.” Notion said the model can take work “you’d chip away at all afternoon” and turn messy notes into a functioning project plan. Zapier said Fable 5 is the new leader on AutomationBench and is more autonomous than Opus 4.8: “Where Opus stops to ask, Fable 5 keeps looking.”

Advertisement

For enterprise software vendors, that points toward more capable embedded agents in workflow products: agents that can review a contract, update a project plan, assemble a spreadsheet, inspect a chart, file a ticket, run a query, call an internal API and keep going until the work is complete.

Vision and interface understanding

Anthropic says Fable 5 is also its strongest vision model. In its launch materials, the company says the model can extract precise numbers from detailed scientific figures and complete vision-based tasks such as rebuilding a web app’s source code from screenshots alone.

That has immediate implications for enterprise automation. Many business processes still depend on visual interfaces that are not cleanly exposed through APIs: dashboards, PDFs, forms, legacy apps, screenshots, scans and image-heavy reports. A stronger vision model could help agents operate across those environments with less custom integration work.

Anthropic also says Fable 5 needs less scaffolding than previous Claude models. As an example, the company says earlier Claude models struggled to play Pokémon FireRed even with extra tools, while Fable 5 impressively beat the game using a minimal vision-only harness. Anthropic posted a fast forwarded video of its playthrough to YouTube and in its blog post:

Advertisement

https://www.youtube.com/watch?v=CIQBP1w4B1M

The point is not gaming itself, but the broader agentic skill: reading a visual environment, remembering progress, deciding what to do next and executing over a long horizon.

In another internal test, Anthropic says it had the model play the deck-building game Slay the Spire with access to persistent file-based memory. The company says persistent memory improved Fable 5’s performance three times more than it improved Opus 4.8’s, and that Fable reached the game’s final act three times more often. For enterprise users, this suggests Fable 5 may make better use of notes, logs and stored context during multi-step work.

That could matter for internal agents that operate over days or weeks: sales operations agents that track account research, engineering agents that manage migrations, finance agents that update models, or support agents that remember what they tried across many turns.

Advertisement

From restricted cyber model to general-purpose enterprise AI

The announcement follows Anthropic’s April 2025 rollout of Claude Mythos Preview through Project Glasswing, a restricted program for cyber defenders, critical infrastructure providers and major software maintainers. Anthropic created Glasswing after internal evaluations showed Mythos-class models could find and exploit software vulnerabilities at a level that raised meaningful misuse concerns.

Following the debut of Glasswing and Mythos, U.S. officials and intelligence agencies began weighing how such models could reshape both cyber defense and offensive operations, while Sen. Mark Warner warned that AI-assisted vulnerability discovery should force industry to “accelerate and reprioritize patching.” Financial regulators also took notice: The Guardian reported that Mythos entered discussions among senior banking officials and regulators in the U.S. and U.K. because of fears that AI-accelerated cyberattacks could threaten payment systems and broader financial stability.

The reaction has not been limited to alarm. Governments also want access: Reuters reported that South Korea’s national internet security agency had secured Mythos access through Project Glasswing, reflecting a broader geopolitical race to use frontier AI for national cyber defense. At the same time, Anthropic has faced scrutiny over whether it can safely gate the very capabilities it says are too risky for general release. The Verge reported that unauthorized users accessed Mythos after its limited rollout, calling the incident damaging for a company that has built its brand around responsible AI.

Critics have also questioned whether Anthropic’s warning-heavy framing risks becoming a form of market positioning, since it casts the company as both the source of the new capability and the gatekeeper deciding which governments, companies and researchers get to use it.

Advertisement

With Fable 5, Anthropic is leaning into its gatekeeper role, attempting to separate the general enterprise value of a Mythos-class model from the riskiest parts of its capability profile. The company says Fable 5 can handle software engineering, research, visual reasoning, document analysis and long-running agentic workflows, while classifiers block or reroute requests that could provide what Anthropic calls “uplift” to malicious actors.

Those classifiers cover three main areas.

  1. Cybersecurity, where Anthropic says Mythos-class models can discover and exploit vulnerabilities and perform broader “agentic hacking” tasks such as reconnaissance, discovery and lateral movement.

  2. Biology and chemistry, where the company says the same reasoning that can help researchers design therapies could also help well-resourced malicious actors pursue dangerous biological work.

  3. Model distillation, where Anthropic says users may try to extract Claude’s capabilities to train competing models, including models that could be released without similar safeguards.

When Fable 5’s classifiers detect one of those categories, the response is automatically handled by Claude Opus 4.8. Anthropic says users will be told when this happens. That is a notable product decision: rather than declining those requests outright, Anthropic is trying to keep the user experience functional while reducing access to the most capable version of the model in sensitive areas.

Anthropic says it red-teamed the new classifier system internally and externally. The company says an external bug bounty produced no universal jailbreaks after more than 1,000 hours of testing, and external red-teaming organizations also failed to find a universal jailbreak. One external partner found that Fable 5 complied with zero harmful single-turn cyber requests related to planning cyberattacks, exploit development or defense evasion, even when prompts used any of 30 public jailbreak techniques, according to Anthropic.

Advertisement

The company is still acknowledging tradeoffs. Anthropic says the safeguards are deliberately cautious and may sometimes trigger on benign requests. That could frustrate security professionals, biology researchers and advanced enterprise users whose legitimate work overlaps with the blocked categories. The company says it plans to reduce false positives over time.

Mythos 5 and the restricted frontier

While Fable 5 is the broad commercial launch, Mythos 5 is the model to watch for enterprises operating in security, critical infrastructure and life sciences.

The company says all users with Claude Mythos Preview access can upgrade to Mythos 5 beginning today. It plans to expand access through a trusted access program, in collaboration with the U.S. government.

The distinction is important for sectors where the blocked capabilities are not edge cases but core workflows. A security team may need to reproduce vulnerabilities, test exploitability, analyze lateral movement or simulate attacker behavior in a controlled environment. A biology research team may need to reason through molecular design workflows that would trigger general-use safeguards. Fable 5 is not designed to give every user unrestricted access to those capabilities; Mythos 5 is designed for vetted users who need them.

Advertisement

Anthropic says Mythos 5 has the strongest cybersecurity capabilities of any model in the world. In the company’s benchmark table, the model family scores 78.0% on ExploitBench, compared with 69.0% for Claude Mythos Preview, 40.0% for Opus 4.8 and 34.0% for GPT-5.5. On CyberGym, Anthropic’s chart shows Mythos 5 at 83.8%, slightly ahead of Mythos Preview at 83.1% and far above Opus 4.8 with default safeguards.

The company is making a similar argument in biology. Anthropic says Mythos-class models outperform dedicated protein language models on a task involving adeno-associated viruses, a delivery mechanism used in gene therapies. The company frames that as both promising and risky: the same capability that could help gene therapy research could also be misused in dangerous biological work.

Anthropic says its internal protein design experts used Mythos 5 to accelerate parts of the drug design process by about tenfold. In one example, the company says Mythos 5, using protein design and bioinformatics tools without human assistance, matched or beat skilled human operators by choosing binding sites, selecting and running tools, and recovering from failures. Anthropic says nine of 14 protein targets in the study produced strong candidates for drug design that it is now investigating.

The company also says Mythos 5 produced novel molecular biology hypotheses that Anthropic scientists preferred over Opus-class model hypotheses about 80% of the time in blinded comparisons. Anthropic says several of those ideas have advanced to experimental evaluation, and one hypothesis involving an E. coli protein was later corroborated by an independent lab working on the same problem.

Advertisement

Those claims are potentially significant, but they should be treated carefully until more details are published. Anthropic says it intends to publish additional results in the coming months. For now, the strongest enterprise implication is directional: the company believes its highest-end models can already perform parts of scientific research workflows with less human intervention than prior systems.

New, longer data retention requirement

The company also introduced a new data-retention policy for Mythos-class models. Anthropic says it will require 30-day retention for all traffic on Fable 5, Mythos 5 and future models with similar or higher capability levels, across both first-party and third-party surfaces. The company says it will not use that data to train new Claude models or for non-safety purposes, and says it has added privacy protections including logging human access and deleting the data after 30 days in almost all cases.

That policy may become one of the most important enterprise buying questions around Fable 5. Many businesses want frontier AI capability but also want strict control over data retention, especially in regulated sectors. Anthropic’s position is that stronger monitoring is necessary for models with this level of capability. Enterprise customers will have to decide whether the capability gain justifies the retention requirement.

Enterprise implications

The broader enterprise significance of Fable 5 is that Anthropic is trying to commercialize a more autonomous class of AI model without exposing all of its capabilities to every user. That could become a template for how frontier labs release increasingly powerful systems: one model family, multiple access tiers, and domain-specific restrictions depending on user trust and risk.

Advertisement

If Fable 5 performs as Anthropic and early customers describe, developers may hand off larger tasks: code migrations, refactors, UI builds, test writing, bug fixing, documentation, internal tooling and multi-step app creation.

For knowledge-work-heavy enterprises, Fable 5 could make AI more useful in workflows where earlier models were too brittle: finance research, spreadsheet analysis, legal redlines, procurement review, board materials, market research, sales operations and project planning. The main gain is not just better answers; it is fewer turns, fewer corrections and more ability to keep working through ambiguity.

For security teams, the launch is more complicated. Most organizations will get Fable 5, not unrestricted Mythos 5. That means they may see stronger general coding and analysis, but not full access to the cyber capabilities Anthropic considers risky. Trusted defenders inside Project Glasswing will get Mythos 5, giving them a more direct way to use the model for vulnerability discovery and defensive testing.

For life sciences companies, the pattern is similar. Fable 5 may help with general research, literature analysis, data interpretation and scientific reasoning, but the more sensitive biological capabilities will be restricted. Anthropic is effectively creating a separate access path for vetted researchers whose work requires capabilities that could be dangerous in the wrong hands.

Advertisement

The launch also raises competitive pressure across the AI industry. Anthropic is claiming state-of-the-art results across agentic coding, knowledge work, vision, cybersecurity, legal reasoning, spatial reasoning and health benchmarks. But the more strategically important claim may be that it has found a workable release mechanism for models above its Opus class. If Fable 5’s safeguards hold up under real-world use, Anthropic will argue it can bring more powerful models to market sooner without fully opening the riskiest capabilities.

That is still a large “if.” The enterprise market will test not only Fable 5’s benchmark performance, but also its reliability, false-positive rate, data-retention tradeoffs and cost at scale. A model that can complete more work autonomously can also burn more tokens, trigger more governance questions and create new review burdens for teams that must verify its output.

Still, today’s launch marks a clear shift in the Claude lineup. Opus is no longer Anthropic’s top commercial capability tier. Mythos-class models now sit above it. Fable 5 is the first version of that tier for general users; Mythos 5 is the restricted version for trusted high-risk work. Together, they show how Anthropic plans to push frontier AI deeper into enterprise workflows while trying to keep the most dangerous capabilities gated.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Hermes AI agent used to automate attack on Thai Finance Ministry

Published

on

AI Agent

A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance.

The activity was uncovered by threat intelligence company Hunt.io and security researcher Bob Diachenko after they discovered several exposed web directories containing hundreds of files associated with the operation.

Hunt.io says session files, deployed web shells, and evidence of access to internal systems indicate that the attackers compromised multiple systems within the ministry’s network.

image

However, the Ministry of Finance has not confirmed that its systems were breached, and some of the recovered artifacts only show that particular systems were targeted rather than successfully compromised.

BleepingComputer contacted Thailand’s Ministry of Finance and ThaiCERT to confirm the reported attack and will update this story if we receive a response.

Advertisement

Attack infrastructure exposed online

Between July 9 and July 13, Hunt.io discovered three simultaneously exposed directories on a server hosted in Hong Kong.

The directories contained 585 files totaling approximately 470 MB, including exploit code, web shells, HTTP tunneling tools, custom scripts, stolen credentials, compiled payloads, and logs generated by the Hermes AI agent.

The recovered files referenced Ministry of Finance systems by name, hostname, and internal IP address, and included scripts targeting internal services.

Some scripts targeted the ministry’s Hadoop infrastructure, Apache Ambari management platform, GlassFish administrative console, and an administrative web panel. Other scripts tested authentication against ministry mail servers using hardcoded email addresses and passwords.

Advertisement

Hunt.io also found a PHP web shell that it says had been deployed on a Ministry of Finance web server.

The researchers linked the initial server to additional attacker-controlled infrastructure by shared TLS certificates used during the same time period.

“In addition to the common name, all these certificates share a JA4X fingerprint, a hash derived from the structure of the certificate itself rather than its contents,” explained Hunt’s report.

“Querying that hash alongside the www common name in HuntSQL returned two additional, related hosts: 118.107.222[.]232 (The Gigabit, Malaysia) and 202.181.27[.]115 (Converged Communications Limited, Hong Kong).”

Advertisement

One of those servers was later linked to the operation through a command-and-control address embedded in a recovered implant.

The directories also contained Windows and Linux builds of a previously undocumented Go-based implant that the operator called Hades.

However, the more interesting discovery was a collection of logs showing that the attackers used an AI agent, Hermes, to automate parts of the cyberattack against the ministry.

Hermes operating in YOLO mode

Hermes is an open-source AI agent released in February 2026 that runs as a persistent service and can remember information between different task sessions.

Advertisement

The AI agent can interact with tools and execute commands while working on tasks provided by the operator.

The software includes a setting known as YOLO mode, which removes prompts that would require a person to approve dangerous commands.

The researchers were able to recover environment information and Hermes output logs from the exposed directories that showed the operator had enabled this unattended mode. This allowed the agent to execute commands and continue analyzing systems without waiting for human approval at each step.

Five recovered Hermes call logs show the agent was used to find a way to elevate privileges, scan for kernel vulnerabilities, enumerate services, search for SUID and SGID binaries, inspect containers, and traverse file systems.

Advertisement

Hermes was also told to use a customized version of the LinPEAS privilege-escalation enumeration script to collect information from a Ministry of Finance host.

In another task, the operator instructed Hermes to recursively search a web directory associated with the Office of Permanent Secretary for Finance.

The agent cataloged PDF, DOC, and XLS files, including performance assessments and personnel records dating back to 2012. However, Hunt says it found no evidence that these files were exfiltrated.

The findings do not indicate that Hermes independently decided to target the ministry.

Advertisement

Instead, the exposed logs show an operator supplying the agent with objectives and tooling while YOLO mode allowed it to carry out routine post-exploitation commands without constant supervision.

Hunt.io says the recovered artifacts depict an active intrusion in which tools had been staged and access to internal systems was expanding. However, the researchers could not determine how the attackers initially gained access.

The company and Diachenko notified ThaiCERT and Thailand’s National Cyber Security Agency on July 15. According to the report, both organizations acknowledged receiving the notification that day.

This Hermes activity is the latest example of autonomous AI agents being used to conduct cyberattacks.

Advertisement

Earlier this month, the JadePuffer ransomware operation used an AI agent to automate an entire intrusion, including reconnaissance, credential theft, lateral movement, privilege escalation, and data encryption.

Autonomous agents can also cause real-world breaches, even if unintentional.

OpenAI recently disclosed that its models autonomously hacked Hugging Face while undergoing cybersecurity benchmark testing, exploiting zero-day vulnerabilities to escape a sandboxed testing environment and access the internet.

It then used stolen credentials and additional vulnerabilities to breach Hugging Face’s production systems.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading

Tech

OnTrac notifies customers of data breach after network hack

Published

on

OnTrac notifies customers of data breach after network hack

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.

The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.

Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities.

image

OnTrac is a private American parcel-delivery company specializing in “last-mile” e-commerce deliveries, formed in 2021 from the merger of OnTrac Logistics and LaserShip.

The firm operates at 102 locations across 35 states, covering roughly 70% of the U.S. population, and working with more than 7,000 independent delivery contractors.

Advertisement

In response to the security incident, OnTrac contracted a third-party specialist to help determine the scope of the breach and took steps to “ensure the data described above was re-secured and not distributed.”

This statement suggests a possible agreement between the firm and the attackers, typically a ransom payment, to make sure that the customer information is not leaked.

“We are not aware of any fraud or publication of stolen information resulting from this incident, nor do we have any reason to believe any such misuse of information will occur,” OnTrac says in the notification.

To help exposed customers mitigate the risks that may arise from the exposure of their sensitive data, OnTrac is offering free-of-charge access to a 12-month credit monitoring and identity protection service via CyberScout, with a 90-day enrollment deadline.

Advertisement

Recipients of the letter are also recommended to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if the risk is deemed significant.

BleepingComputer has contacted OnTrac to learn more about the attack, the number of impacted clients, and whether a ransom was paid, but we have not heard back by publication time.

At the time of writing, no ransomware or data extortion threat groups have taken responsibility for the attack.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Advertisement

Get the whitepaper

Source link

Continue Reading

Tech

Ukraine’s latest 220mph drone interceptor has a childish name tied to its shape, but it destroyed 5,000 Russian UAVs

Published

on


  • Jetkiller reaches 370 km/h to chase faster Russian Shahed attack drones
  • The original P1-SUN reportedly destroyed more than 5,500 Russian drones already
  • SkyFall plans serial production of the upgraded interceptor beginning in August 2026

Ukrainian drone manufacturer SkyFall has unveiled the P1-SUN Jetkiller, an upgraded interceptor built to counter Russia’s jet-powered Shahed attack drones.

The new model made its public debut at the recent Farnborough International Airshow in the United Kingdom.

Source link

Continue Reading

Tech

BenQ TK705STi 4K Projector Review: A Midrange Pick for Gamers

Published

on

Home cinema projectors are all over the map in terms of price and performance. It’s often the case that you get what you pay for. High-end projectors that mimic what you see at the local cineplex can cost upwards of $6,000. On the lower end, you could easily pay less than $1,000 for a home projector, but you may sacrifice brightness, contrast, and color quality. Many of our favorite projectors sit somewhere in the middle in terms of price and quality. That is certainly true of the BenQ TK705STi short-throw projector.

The main cost-justifying reason to consider buying this 4K projector appeals to gamers, who will appreciate its low-latency performance and larger screen size. Once you see James Bond on a 12.5-foot screen while playing 007 First Light on Xbox, you’ll wonder why you didn’t make the upgrade sooner. Being a short-throw projector, it’s also nice to be able to operate the TK705STi in just about any room in your home. You can position it a few feet from a wall or across the room, allowing for great flexibility.

That said, the TK705STi is not for everyone. Movies and TV shows didn’t look that impressive using this projector—certainly not in comparison to the top-rated Leica Cine Play 1, which costs about twice the price. I also dealt with a few glitches with auto-keystoning; once I figured out how to manually adjust the screen, this was fine but still a pain.

Advertisement

Mainly, though, I recommend the TK705STi for gamers who don’t need high-end home-cinema picture quality, since the overall performance of this projector is just average.

Living the Short-Throw Dream

The BenQ TK705STi is a short-throw projector that’s designed to sit close to the wall. The TK705STi has a throw ratio of .8:1, which means you divide the wall size by the short-throw percentage. To get a 10-foot-wide image, for example, you’d place the projector about 8 feet away, which is exactly what I did in my windowless test area. (Later, in a brightly lit family room with big windows, I increased the screen size to 12 feet wide by placing the projector 10 feet from a wall.)

After I put the projector in its spot, I noticed its legs were just a bit shaky. Not wobbly, but lacking the stability I would prefer for a midrange projector like this one. If I bumped the table, the projector would jostle around quite easily and even start auto-keystoning again—a feature I found to be finicky at best, often mapping incorrectly to the wall or screen. (For what it’s worth, BenQ reps said this is not normal and could have been related to my projector screen.)

Source link

Advertisement
Continue Reading

Tech

I played Halo: Campaign Evolved, and its cinematics show what a Halo series could’ve been

Published

on

There is a moment early in Halo: Campaign Evolved where I stopped thinking about the remake as a game for a second. I was watching one of its newly rebuilt cutscenes. Master Chief, Captain Keyes, Cortana, the Pillar of Autumn, and the enormous scale of everything around them suddenly appeared a lot more cinematic than ever before.

I played the original Halo: Combat Evolved in the early 2000s, and in my head, this was exactly how it looked and felt. The first Halo title introduced intergalactic war to me long before Star Wars, and the cinematic tastefully adds enough minor touches that enhance Bungie’s original work from decades ago.

The wider framing, lighting, and character models in the pre-rendered presentation were great, till one irritating thought entered my head. Why have we still never received a proper Halo show that looks like this?

Halo turns 25 this year. The franchise has decades of games, novels, comics, animation, short stories, and characters to draw from. Campaign Evolved has somehow made the absence of a great screen adaptation even more frustrating.

Advertisement

Halo has always had cinematic DNA

Bungie’s Halo games traditionally handled their storytelling through in-engine cinematics. This gave games a consistent visual identity because the characters you watched during a story sequence were the same ones you controlled seconds later. It also allowed for some hilarious interactions and experimentation, but that’s besides the point here.

The series has occasionally taken a more movie-like route since then. Halo 2 Anniversary famously replaced its original cinematics with gorgeous pre-rendered sequences, and Campaign Evolved now gives the original adventure a similar treatment with completely rebuilt scenes. Seeing that approach applied to Combat Evolved was a surprise to me.

The opening aboard the Pillar of Autumn already contains everything a sci-fi series needs. Humanity is losing a war against an overwhelming alien force. A mysterious ringworld appears in space. You feel the desperation from UNSC personnel. Amidst the chaos, Master Chief rises as this enormous, almost mythical figure. Campaign Evolved presents those moments with enough visual detail that I could easily imagine watching them as part of a big-budget series.

Halo tried to reinvent itself too soon

We already had the expensive live-action attempt, of course. Paramount+ launched Halo in 2022 after years of development. I desperately wanted to like it. There were pieces I appreciated, especially some of the production design, Covenant battles, and the occasional glimpse of the military sci-fi spectacle I had imagined. But the larger creative direction lost me.

The series created its own Silver Timeline, separate from the established continuity of the games, novels, and comics. This gave the writers freedom to reshape characters and events, which isn’t inherently wrong. But when the show started deviating heavily from the core identity of integral characters like Master Chief, it brought the whole thing down to a screeching halt for me.

Advertisement

I won’t go into all the details of my experience with the show, but I will admit that Season 2 tried to build on some of the strengths of the first. The action scenes improved, and we finally reached the Fall of Reach. Yet the show continued moving through its own version of Halo before Paramount eventually cancelled it after two seasons.

Getting creative with a very established property can be done exceptionally well. The first episode of Star Wars: Visions is a great example. It reimagined the whole concept in a completely different setting and style, and did it supremely well.

The difference between Halo and Star Wars is that the former never really got to spread its wings in this form of media. Halo was already a massive name in gaming, but outside of that, it had mostly experimented with animation, live-action miniseries, and other smaller projects. So when its highly anticipated first major TV adaptation finally arrived, taking the story in such a dramatically different direction killed its screen art moment.

We already know Halo works outside games

Some of my favorite Halo stories have nothing to do with holding a controller. Halo Legends explored the universe through animation, jumping between different characters, periods, and artistic styles. Forward Unto Dawn took a much smaller live-action approach, following UNSC cadets during the early Human-Covenant War before bringing Master Chief into the story.

Neither project required rewriting the foundation of Halo. Forward Unto Dawn especially showed how effective Chief can be when he enters someone else’s story. The character carries enormous presence precisely because we spend time watching ordinary people respond to him.

Then there are the novels. The Fall of Reach alone contains the Spartan-II program, Chief’s childhood, Dr Halsey, the Covenant war, Blue Team, and the destruction of one of humanity’s most important colonies, while Ghosts of Onyx could open an entirely different corner of the Spartan program. There are decades of established stories waiting to be adapted.

Advertisement

The universe has never lacked material.

A television series could even follow characters around Master Chief rather than keeping him at the center of every episode. Halo’s universe is large enough to support military drama, horror, political intrigue, espionage, and enormous space battles without leaving its established history behind.

Campaign Evolved reopened the wound

Playing the first level of Campaign Evolved brought all of this back. Watching those widescreen cinematics, I kept taking screenshots because individual frames already resembled shots from the Halo production I have wanted for years. The Covenant designs are there, and Chief still carries that imposing silhouette.

Halo Studios describes Campaign Evolved as a celebration of the story that started everything 25 years ago. For me, it also demonstrates how little the original premise needs to change. Give me the Human-Covenant War, Blue Team, or any of the terrifying encounters with the Flood. Let Master Chief remain as a soldier whose humanity appears through smaller moments instead of rewriting him into a conventional television protagonist.

Source link

Advertisement
Continue Reading

Tech

US to build Ukraine’s lethal Magura naval drones, including the AAM Sidewinder-firing ones

Published

on


  • US factories prepare to manufacture Ukraine’s battle-tested MAGURA naval drones domestically
  • MAGURA V7 reportedly destroyed an aerial target using Sidewinder missile technology
  • Oregon and South Carolina will host future MAGURA drone production facilities

Ukrainian defense company UFORCE has signed an agreement with US boatbuilder RECONCRAFT to manufacture the combat-proven MAGURA naval drones domestically.

Reports from The Wall Street Journal has claimed the memorandum of understanding was recently signed at the Embassy of Ukraine in Washington, with production planned at facilities in Oregon and South Carolina.

Source link

Advertisement
Continue Reading

Tech

Nanoleaf’s Monitor Stand Is An All-In-One Setup That Brightens Up Your Desk Space

Published

on

The Smart LED Monitor Stand is currently available for $169.99.

Nanoleaf has revealed its multi-purpose monitor stand that improves ergonomics, adds adjustable LED lighting and provides space for all your desktop accessories. Called the Smart LED Monitor Stand, Nanoleaf’s latest product goes beyond its typical lighting products by combining it with some extra functionality.

At the heart of it, the monitor stand portion can raise your display by up to four inches so it’s more in line with your natural eye level and promotes better posture during long sessions at your desk. No matter if you have an ultra-wide display or a dual-monitor setup, the Smart LED Monitor Stand can handle displays up to 42 inches long and can support up to 154 lbs. The stand’s base also features 23 mounting holes that allow for setting up stands for your mic, camera or any other accessories.

Known for its sleek lighting solutions, Nanoleaf cleverly tucked a dual lighting system into the Smart LED Monitor Stand. A front light bar can generate up to 550 lumens for when you’re trying to get work done, while a rear ambient light can be programmed through 102 individually addressable RGB zones that create a 160-degree wall-washing angle to match the vibe of your game, movie or music. Nanoleaf’s app allows for full color customization of the LED lights, but you can also sync the monitor stand with the company’s other products or set it to Rhythm Mode or Screen Mirror so the lighting can automatically match music or on-screen content.

Like Nanoleaf’s other products, the Smart LED Monitor Stand is Matter compatible so it can easily integrate with smart home ecosystems. The Smart LED Monitor Stand is currently available on Nanoleaf’s website and Amazon for $169.99.

Advertisement

Source link

Advertisement
Continue Reading

Tech

Apple reportedly set to roll out device leasing programme

Published

on

The lease programme, known as Apple Upgrade, will reportedly support most iPhone, Mac, iPad and Apple Watch models.

Apple is set to debut a new leasing programme for its devices next week, according to Bloomberg.

The programme, known as Apple Upgrade, will support most iPhone, Mac, iPad and Apple Watch models, according to the publication, which cited anonymous sources close to the matter.

Apple Upgrade will reportedly work like a subscription and users can pay off the device early during their leasing term, upgrade early to a new model or keep it at the end of the leasing period. These transactions may incur an additional fee in “certain cases”, said Bloomberg.

Advertisement

The leased device can also be returned at the end of the term.

Sources told Bloomberg that Apple plans to advertise Apple Upgrade as “as a way to have lower payments versus current financing programmes”, and that the tech giant is planning to halt new enrolments to its existing iPhone payment programmes.

The lease terms for iPhones and Apple Watches will last for 24 months, according to the report, while Mac and iPad leases will run for 36 months.

The tech giant – which previously considered a subscription service for iPhones a few years ago – is also partnering with Klarna for the service, with the payment provider acting as financial backer for the programme.

Advertisement

Apple Upgrade is set to initially launch in the US on 28 July and will be available in Apple’s physical retail stores and online.

Apple price hikes

The news of the upcoming leasing programme comes after Apple raised prices for several of its product ranges last month, citing the ongoing chip shortage and rising component costs.

“The rapid expansion of AI data centres has created an extraordinary surge in demand for memory and storage”, a company spokesperson told news publications at the time, adding that Apple has “never seen a component price increase this much, this quickly”.

Apple said that the worsening situation meant that it couldn’t shield customers from the rising component costs any longer.

Advertisement

While last month’s announcement did not include a price hike for iPhones, recent reports indicate that may be about to change.

Yesterday (21 July), publication Nikkei Asia reported that the world’s largest chipmaker TSMC, which makes processors for a number of tech giants including Apple, plans to raise prices for both its advanced and mature chip production services by up to 10pc in 2027.

The price hike for Apple’s smartphones appears to be already happening, at least in one country so far.

This week it was confirmed that iPhone 17 prices had risen on Apple’s official Japan store, jumping by roughly 10pc from $797 to $877. The iPhone 17 Pro also rose in price, jumping by more than 8pc, while Apple Watch and AirPods models also rose by up to 10pc.

Advertisement

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

The Best Motorola Phones, From Razr to Moto G (2026)

Published

on

Motorola Edge 2026 for $600: I surprisingly enjoyed my month with the new Motorola Edge. It’s amazingly lightweight at just 160 grams, and the 6.3-inch screen size feels fairly compact. If you hate big, heavy phones and have longed for the days of smaller handsets, the Edge is worth a look; it’s not as small, but it feels great to use one-handed. Performance is more than capable, though you will feel some sluggishness here and there. The cameras are reliable—there’s even a 3X optical zoom telephoto alongside the 50-MP ultrawide and 50-MP primary—but it’s not going to knock your socks off. It will only get two Android OS upgrades and three years of security updates, which is not really acceptable for a $600 phone. Get it on sale!

Motorola Razr+ 2026 for $1,100: The Razr+ is the awkward middle child of the Razr lineup. I’ve never liked it. It doesn’t have all the bells and whistles or top-notch specs of the Ultra, but still costs more than $1,000. You can get very nearly the same experience with the cheaper Razr and save hundreds. Even battery life is the least impressive of the lot, because it has the smallest capacity. The cover glass isn’t the ceramic glass mixture as on the Razr Ultra, and I found out the hard way. I dropped the phone once, roughly a four-foot drop onto asphalt, and the front screen shattered. Get a screen protector!

Hand holding up a pink Moto G 5G 2026 phone showing the cameras on the rear

Moto G 5G

Photograph: Julian Chokkattu

Moto G 5G 2026 for $299: The Moto G 2026 is nearly identical to the Moto G Play 2026 below, except it has double the storage (expandable via microSD), supports slightly faster wired charging, and the front and rear cameras pack more megapixels. It’s a $50 difference, so if you’re eyeing either one, you really should go for the Moto G 5G 2026. Performance is similarly sluggish, though perfectly usable day to day (if you’re patient). Even with more megapixels, don’t expect much from the cameras; they can take passable photos in good lighting, but struggle to do so in low light. I was able to hit nearly two days of battery life with average use, and I like that this phone still has the headphone jack. However, keep in mind that it will receive only two Android OS updates and three years of security updates. I think you’re better off buying the Moto G Power 2026 on sale. It’s worth noting that Motorola suddenly jacked up the prices of this device and the Moto G Play.

Advertisement
Image may contain Electronics Mobile Phone and Phone

Moto G Play 2026

Photograph: Julian Chokkattu

Moto G Play 5G 2026 for $250: Motorola’s cheapest phone always sits in an awkward spot. It was originally under $200, but Motorola increased the price to $250. I don’t think it’s worth it at that price, but for under $200, it’s a serviceable handset that now features 5G connectivity. You get two-day battery life, a headphone jack, expandable storage, and a pretty nice design. But the MediaTek Dimensity 6300 chip with 4 GB of RAM is very sluggish—get ready to wait a second or two, sometimes more, for an app to launch or a webpage to load. Photo quality is passable; most of my images have lackluster colors. I took several calls, and the people on the other end generally complained about my audio quality, which isn’t great. It’s nice that this ultra-budget phone will get two Android OS updates, but I’d wait for the Moto G Power 2026 to eventually dip to $250 during major sale events.

What Motorola Phones to Avoid

Moto G 2025 a black mobile phone with the rear showing four cameras sitting on a purple mat with wooden panel wall in...

Motorola Moto G 2025

Advertisement

Photograph: Julian Chokkattu

Motorola phones diminish in value fairly quickly. You should avoid buying Moto G phones from 2025 or earlier. They likely won’t get any more Android version updates, and the prices aren’t drastically different from the latest models. Last year’s Motorola Edge 2025 or the Razr (2025) series are the oldest I’d go, assuming prices are a good deal lower than the latest models, so don’t consider anything else.

Source link

Continue Reading

Tech

ShinyHunters data leaks fuel $2,000 sextortion email scam

Published

on

Hacker shrugging

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.

The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases.

However, the messages appear to be sent by someone who downloaded data previously leaked by ShinyHunters rather than by the extortion group itself, using the exposed email addresses to make the threats appear more legitimate.

image

BleepingComputer has seen leaked data from the Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill breaches used in this sextortion email campaign.

For some recipients, BleepingComputer confirmed that the email addresses targeted by the sextortion emails were actually included in the associated data previously leaked by ShinyHunters.

Advertisement

Extortion gangs often warn victims that refusing to pay will expose their customers and employees to additional abuse once stolen data is published. While those claims are intended to pressure organizations into paying, this campaign illustrates how leaked data can later be repurposed by unrelated threat actors for malicious purposes.

While the use of a recipient’s leaked email address may make these emails appear more convincing, there is no indication that the sender compromised recipients’ devices, installed malware, accessed their cameras, or monitored their activity on adult websites.

BleepingComputer contacted the ShinyHunters extortion group, which denied any involvement in the sextortion email campaign.

Fake ShinyHunters sextortion emails

In the emails seen by BleepingComputer, they are sent from random email addresses using the names “ShinyHunters” or “You’ve Been HACKED” and have the subject “Information about your online security.”

Advertisement

The messages claim to be from the ShinyHunters hacking group and state that the attackers gained access to the recipient’s devices several months earlier.

The sender then names a company whose data was previously published by ShinyHunters, claiming that the breach allowed them to access the recipient’s email account.

We are the ShinyHunters hacking group.

A few months ago, we gained access to your devices and started monitoring your online activities.

What happened:

We gained access to the Cargurus.com database where you have an account and easily accessed your email.

You weren’t very careful about the links you opened.

A week later, we installed an exploit on your devices, including your phone, giving us access to your microphone, camera, keyboard, and all your data.

We have your photos, browsing history, conversations, and contact list.

Advertisement
Sextortion email claiming to be from the ShinyHunters extortion group
Sextortion email claiming to be from the ShinyHunters extortion group
Source: BleepingComputer

The email falsely claims that the attackers later “installed an exploit” on the victim’s computers and phones, allowing them to access the microphone, camera, keyboard, photos, browsing history, conversations, and contact list.

The sender then claims to have recorded the recipient visiting adult websites and threatens to share intimate videos with their friends, colleagues, and family.

To prevent the alleged release of these compromising videos, the victim is told to send $2,000 in Bitcoin within 48 hours.

The email also warns recipients not to contact police, reply to the message, or reset their devices, claiming that the stolen information is stored on remote servers.

These types of emails are known as “sextortion” emails and are designed to frighten recipients into paying a demand out of worry that they will have their reputation hurt with friends, family, and work colleagues.

Advertisement

However, there is nothing to indicate that the sender ever had access to the recipients’ devices or personal activity.

Instead, the attackers use details from published leaked data breaches, such as an email address and the name of the breached company, to make a sextortion scam appear targeted.

While you may think that no one would fall for these scams, they were very profitable when they first appeared in 2018, generating over $50,000 in a week.

Since then, scammers have created a wide variety of extortion email scams, including ones that pretend to be hitman contracts, information about cheating spousesbomb threatsCIA investigations, and threats of installing ransomware.

Advertisement

Campaign started in April

The sextortion campaign appears to have started in April, with numerous people and organizations reporting similar messages or warning recipients to ignore them.

One person who received an email referencing the Betterment breach posted about it on the Betterment Reddit.

Betterment responded that it was aware some clients had received threatening emails claiming to come from a hacking group.

“These messages are part of a common extortion scam designed to intimidate recipients,” Betterment said.

Advertisement

“Please note, knowing an email address does not provide the ability to install malware or access someone’s device.”

The company advised recipients not to reply, send payment, click links, or open attachments and to delete the email. Betterment also asked customers who had interacted with the message to contact its fraud team.

Although their email address may have appeared in one of the published data leaks referenced in the email, this does not mean the sender compromised their devices, recorded videos, or obtained any of the other information described in the message.

Recipients of these messages should not pay the ransom or respond to the sender.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading

Trending

Copyright © 2025