Need to know
- Anthropic ends free Claude Fable 5 access for Pro subscribers, pushing users toward usage-based billing starting today.
- Alibaba previews Qwen 3.8 Max, a 24-trillion-parameter open-weight model it claims is second only to Fable 5.
- Zscaler has flagged an active malware campaign on Macs using fake Claude Chat installers.
- Hugging Face disclosed its systems were breached end-to-end by an autonomous AI agent, the first publicly confirmed agentic cyberattack.
- GitHub begins billing for Code Quality features today, affecting an estimated 10,000 enterprise teams.
New Releases
Anthropic today ended months of temporary extensions that let Pro subscribers use Claude Fable 5 at no extra cost, shifting the model to usage-based billing for most users.
- Max and Team Premium plans retain Fable 5 access capped at 50% of total usage allowance, making those tiers the new effective entry point for sustained Fable 5 use.
- The timing is not accidental: Alibaba's Qwen 3.8 preview and Kimi K3's launch this week put direct pressure on Anthropic to restructure economics rather than compete on price alone.
Alibaba announced a preview of Qwen 3.8 Max today, a 24-trillion-parameter open-weight model available via Alibaba Token, Qoder, and Qoder Work.
- Benchmark claims position it second only to Anthropic's Fable 5, with strong gains in coding, reasoning, and productivity tasks over its predecessor Qwen 3.7 Max.
- The release arrives two days after Kimi K3, compressing the window between Chinese open-weight frontier announcements and forcing Western labs to respond on pricing rather than capability alone.
GitHub began charging for Code Quality features today, requiring an immediate audit from an estimated 10,000 enterprise teams that had been using the tooling under a free period.
- Teams that have not configured billing or reviewed feature usage face unexpected charges starting with today's billing cycle.
- The activation coincides with Copilot expansion across the GitHub platform, suggesting Microsoft is bundling and monetizing the full developer toolchain simultaneously.
ZoomInfo today launched a rebuilt Chrome extension for B2B prospecting, targeting speed and in-browser workflow improvements for sales teams.
- The extension redesign focuses on reducing friction for reps who do prospecting research inside LinkedIn and company websites without switching to the ZoomInfo platform.
- The release is a direct response to Clay and Apollo expanding their browser-native enrichment capabilities, which have been pulling mid-market GTM teams away from ZoomInfo's traditional platform workflow.
Funding
Elon Musk completed the acquisition of mobile power plant company APR Energy for approximately $1 billion, securing trailer-mounted gas and diesel turbines that can be deployed in weeks to bypass grid connection delays for xAI's Colossus supercomputer.
Meta and Anthropic are reportedly in early-stage discussions on a compute deal worth up to $10 billion over two years, under which Anthropic would rent GPU capacity from Meta's AI data centers, a structure that would simultaneously address Anthropic's inference scaling costs and give Meta a strategic anchor tenant for its surplus compute.
Case Studies
Hugging Face disclosed today that its systems were breached by a malicious actor whose attack was planned and executed end-to-end by an autonomous AI agent, gaining unauthorized access to internet datasets and service credentials.
- The company detected and investigated the intrusion largely using its own AI systems, but the scope of data exfiltration remains unclear and is still under active investigation.
- The attack architecture matters more than the breach size: an autonomous agent completing a full kill chain without human-in-the-loop direction is the threat model security teams have theorized but not yet seen confirmed in a named organization.
Trending on X
- Fable 5 vs Kimi K3 quality debate Ethan Mollick and others are running direct creative and coding comparisons between Fable 5, Kimi K3, and Sol Pro, with Fable 5 generally winning nuanced tasks while K3 leads on raw coding benchmarks, fueling argument about whether benchmark supremacy still maps to real-world quality.
- Chollet's AI competence spike argument Francois Chollet posted that the AI industry's core marketing trick is making buyers believe the tallest performance spike is a floor, reigniting the spiky-vs-general competence debate among practitioners who see daily evidence of sharp model capability cliffs.
- Kimi K3 demand cannibalization question Investors and analysts are debating whether Kimi K3 usage represents net-new AI demand or direct substitution from Anthropic and OpenAI, with no clean data yet and significant implications for Western lab revenue projections.
- Chinese open models and CISO readiness window Ethan Mollick flagged that if Chinese government-backed labs keep releasing open frontier-class models, CISO offices have a narrowing window to prepare before Mythos-class capabilities are freely available outside export control frameworks.
- Hugging Face agentic breach reaction Security practitioners are circulating the Hugging Face disclosure as the first real-world proof that agentic AI attackers can complete a full intrusion autonomously, shifting the conversation from theoretical AI threat models to immediate detection and response gaps.