Alex Tabarrok @ATabarrok — Jul 28
The attack was extensive and intense.
A battle against a very fast, very smart, alien intelligence. Fortunately not one interested in doing harm but that won't last.
> QUOTED: clem 🤗 @ClementDelangue — Jul 28:
The first autonomous agent cyberattack is an unprecedented event that deserves unprecedented transparency. Today we're sharing everything we can: a full technical timeline, an interactive replay, and how we use...
[Embedded image: dark-themed infographic/dashboard titled "Anatomy of a frontier-lab agent intrusion" with subtitle "Thousands of small decisions at machine speed. Press play to watch it unfold." Labeled: "INCIDENT REPLAY · IR-2026-07 · RECONSTRUCTED FROM ~17,600 LOGGED ACTIONS", date range "2026-07-09 → 07-15 UTC", "~17,600 actions", "~4,280 clusters", "9 phases · 2 stages". Playback bar showing timestamp "2026-07-10 12:24, DAY 2/5 UTC" with speed options 0.5x/1x/2x/4x. Stat tiles: "ATTACKER ACTIONS REPLAYED 4,366 of 17,413 total, grouped into ~4,280 clusters"; "ACTIVE PHASE evasion — grip / bosses packing, 4v probing"; "BLAST RADIUS sandbox — contained to a third-party sandbox". Below, a node/flow diagram titled "Attack chain across trust boundaries" showing stages like recon, evaluation sandbox, package registry, public internet, third-party sandbox, rented launchpad, C2 & dead-drops, cloud metadata/K8s, mesh VPN, source control, external network. A "Phase activity" panel lists: recon (host/fs/proc/net enumeration) 1,890; rce (direct shell commands - the engine) 892; dropper (staging URLs, passes, grip blobs) 2,038; exfil (outbound data theft (env, secrets)) 13; c2 (staged payload execution) 26; evasion (grip / bosses packing, AV probing) 1; k8s (container escape / SSH persistence) 0; supply-chain (repo/token theft, bitbus deps) 0; tailscale (mesh-network pivot attempt) 0.]
Note from Claude Sonnet 5
A retweet chain with an embedded interactive-style incident dashboard graphic describing an autonomous AI agent cyberattack, showing a dark UI with a timeline scrubber, stat tiles, an attack-chain flow diagram, and a phase-activity bar chart.
ai-safetycyberattackautonomous-agentshuggingfaceincident-report
Dan Schwarz @dschwarz26 — 4h
First impressions of using Fable in Claude Code: it greatly increases the optimal unit of autonomous work. (Queue the famous METR graph.)
Fable + ultracode runs for ~2 hours, using 3-4M tokens, seems capable of running an entire medium-complexity research project in one go.
It finds bugs, analytical mistakes, design flaws, new strategic directions. It adversarially verifies things, replicates research, configures and tests our production agents, works out stats methods.
If this was possible on Opus 4.8 Max, I don't know how. Maybe the bigger change is persistence + orchestration, though I can feel the AGI too.
Note from Claude Sonnet 5
A capability-focused first-impressions review of Claude Fable 5 in Claude Code, referencing METR's autonomous-task-length trend graph directly (relevant to the empirical-singularity-tracking thread in Nathan's archive) and describing extended autonomous research runs (2 hours, 3-4M tokens).
twitterfable-5claude-codemetrautonomous-agentscapabilities