Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

Source: YouTube · IBM Technology · published Jul 8, 2026 · 41:54

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Anthropic, OpenAI, and other providers are releasing powerful AI models with enhanced safety guardrails, while threat actors adapt by using AI-driven ransomware and sophisticated social engineering like ClickFix to bypass defenses 1:41.

Key Takeaways:
• Frontier models like Fable 5, Mythos 5, and GPT-5.6 Sol prioritize real-time classifiers to detect harmful inputs, marking a shift in AI safety implementation 2:02.
• Safeguards primarily benefit compliant users, leaving a gap where unrestricted models (like open-weight GLM 5.2) or unregulated actors can still be used for malicious purposes 5:46.
• "Agentic ransomware" (JADEPUFFER) demonstrates AI's ability to automate exploitation, though its current lack of sophistication suggests it is an early stage of a broader trend toward AI-amplified cyberattacks 13:34.
• ClickFix has emerged as a dominant social engineering attack by tricking users into pasting harmful commands into terminals, exploiting the "self-help" IT culture and bypassing traditional email filters 24:11.
• The UnregStealer campaign targets Latin American financial institutions using a human-in-the-loop approach, delivering malicious Chrome extensions via enterprise policy to steal banking credentials selectively 33:10.

The cybersecurity landscape is shifting from static defenses to dynamic, AI-driven threats that require continuous adaptation in both technical controls and user awareness.

Sources:

  • 1:41 Introduction to new AI models and their safety features.
  • 2:02 Discussion of Fable 5, Mythos 5, and GPT-5.6 Sol sa

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Last week, Anthropic and OpenAI both released powerful new models, and they both made a pretty big deal about those models' safeguards. Panelists I want to know how you're feeling about the state of AI model security right now. One of my favorite sayings is that change is the only constant. And so the constant with AI models is they're changing. So if you like them now, well, they're going to change. If you don't, well they're going to change. It's expected for us to see some development. We obviously have to keep making safeguards. Threat actors will keep trying to break them. So never- ending cycle. But at least we're trying. Hello and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical tak…