The panel discussed the release of advanced AI models like Anthropic’s Fable 5 and OpenAI’s GPT-5.6, emphasizing the ongoing challenges of implementing effective safeguards amid evolving threats such as agentic ransomware, ClickFix social engineering attacks, and sophisticated credential theft campaigns like Unreg Stealer. They highlighted the need for a systemic, collaborative defense approach combining technical measures, user education, and strict access controls to address the dynamic and adversarial nature of AI-driven cyber threats.
Last week saw the release of powerful new AI models from Anthropic and OpenAI, including Anthropic’s Fable 5 and Mythos 5, and OpenAI’s GPT-5.6 Saul, all emphasizing advanced safeguards to prevent misuse. The panel discussed the evolving nature of AI models and the ongoing challenge of implementing effective safeguards, noting that while these protections are crucial, they are part of a continuous cycle where bad actors will always attempt to bypass them. The introduction of classifiers—smaller AI systems monitoring interactions in real-time—was highlighted as a promising approach, though concerns remain about their potential to be overly restrictive and the difficulty in fully preventing jailbreaks.
The conversation also touched on the emergence of open-source models like China’s GLM 5.2, which reportedly matches Mythos-level capabilities but with fewer restrictions. This development lowers the barrier to entry for potentially malicious use, complicating the safeguard landscape. Panelists agreed that while standards and frameworks for assessing jailbreak techniques are being developed, the dynamic and adversarial nature of AI security means that vulnerabilities will continue to surface, requiring a systemic and collaborative approach to defense beyond just model-level protections.
The discussion then shifted to the recent report of Jade Puffer, described by CISDig as the first agentic ransomware driven by an AI language model. While some panelists expressed skepticism about labeling it as truly agentic ransomware due to its relatively unsophisticated tactics and limited impact, others saw it as an inevitable early example of AI-driven attacks that mimic human behavior but operate at greater speed and scale. The rapid exploitation timeline and self-narrating code were noted as indicators of AI involvement, though the overall consensus was that such attacks are a natural progression in cyber threats and underscore the need for preparedness.
Next, the panel examined the rise of ClickFix, a social engineering attack technique that tricks users into pasting malicious commands into their system terminals. This method has quickly become a dominant initial access vector, partly because it exploits human trust and the increasing tendency for users to self-diagnose and fix technical issues. Attackers are adapting by developing evasive maneuvers, such as using AppleScript on Macs to bypass warnings. The panel emphasized that technical defenses alone are insufficient against such attacks, which target the human element, and stressed the importance of user education, role-based access controls, and restricting terminal command execution to mitigate risks.
Finally, the episode featured a deep dive into Unreg Stealer, a sophisticated browser-based credential theft campaign targeting Latin American financial institutions, particularly Brazilian fintech and payment platforms. The attack uses social engineering to install malicious Chrome extensions silently via enterprise policies, enabling real-time credential theft with human operators selectively activating payloads against valuable targets. The panel highlighted the complexity of defending against such adaptive, targeted campaigns and recommended strict controls on browser extension installations, PowerShell hardening, user awareness, and thorough remediation steps including session invalidation and credential rotation to effectively combat infections.