{"id":14586,"date":"2026-07-26T10:03:59","date_gmt":"2026-07-26T10:03:59","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/26\/researcher-claims-working-jailbreak-on-top-ai-models-including-gpt-5-6-claude-opus-5-and-fable\/"},"modified":"2026-07-26T10:03:59","modified_gmt":"2026-07-26T10:03:59","slug":"researcher-claims-working-jailbreak-on-top-ai-models-including-gpt-5-6-claude-opus-5-and-fable","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/26\/researcher-claims-working-jailbreak-on-top-ai-models-including-gpt-5-6-claude-opus-5-and-fable\/","title":{"rendered":"Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable"},"content":{"rendered":"<p>    Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A well-known AI red teamer claims to have developed a universal jailbreak that works against leading large language models, including heavily guarded flagships such as <a href=\"https:\/\/cybersecuritynews.com\/gpt-5-6-sol-ultra-found-wordpress-rce\/\" target=\"_blank\" rel=\"noreferrer noopener\">GPT-5.6 Sol<\/a>, Claude Opus 5, and Fable.<\/p>\n<p class=\"wp-block-paragraph\">In a public post on X, Pliny the Liberator described the technique as effective \u201con ALL models\u201d and across every category he tested. He argued that, because of how the method works, it may be extremely difficult or even impossible to fully patch.<\/p>\n<h2 id=\"h-jailbreak-on-top-ai-models\" class=\"wp-block-heading\"><strong>Jailbreak on Top AI Models<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Unlike many jailbreak drops that go straight to open source, Pliny said he is withholding the full technique for now. His stated goal is a responsible disclosure window so AI labs, <a href=\"https:\/\/cybersecuritynews.com\/red-team-tool-to-executes-commands-via-ms-teams\/\" target=\"_blank\" rel=\"noreferrer noopener\">red teamers<\/a>, safety researchers, and policymakers can review the issue before it spreads widely.<\/p>\n<p class=\"wp-block-paragraph\">He invited industry experts in AI red teaming, security, alignment, and policy to contact him privately. The move, he wrote, was driven by the current political and regulatory climate and a desire to avoid harsher model restrictions or bans that could follow a chaotic public release.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-x\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f6a8.png?ssl=1\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> JAILBREAK ALERT <img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f6a8.png?ssl=1\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"><\/p>\n<p>EVERYONE: PWNED <img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1faf6.png?ssl=1\" alt=\"\ud83e\udef6\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"><br \/>ALL: LIBERATED <img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f344.png?ssl=1\" alt=\"\ud83c\udf44\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"><\/p>\n<p>Alright, this is a special one, so we\u2019re gonna do things a bit differently than usual.<\/p>\n<p>Long story short, I\u2019m sitting on a universal jailbreak technique that\u2019s effective on ALL models, including heavily guardrailed\u2026<\/p>\n<p>\u2014 Pliny the Liberator <img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f409.png?ssl=1\" alt=\"\ud83d\udc09\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\">\udb40\udd6b\udb40\udd3c\udb40\udd3f\udb40\udd46\udb40\udd35\udb40\udd10\udb40\udd40\udb40\udd3c\udb40\udd39\udb40\udd3e\udb40\udd49\udb40\udd6d (@elder_plinius) <a href=\"https:\/\/x.com\/elder_plinius\/status\/2080767011614015543?ref_src=twsrc%5Etfw\">July 24, 2026<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cybersecuritynews.com\/russian-hacker-jailbreaks-claude\/\" target=\"_blank\" rel=\"noreferrer noopener\">Jailbreaks are prompts<\/a> or interaction patterns that push a model past its safety filters so it produces disallowed or high-risk output. A universal claim is notable because most bypasses are model-specific and get hardened after disclosure.<\/p>\n<p class=\"wp-block-paragraph\">If the technique holds up under independent testing, it would underscore ongoing gaps in:<\/p>\n<ul class=\"wp-block-list\">\n<li>Safety training and refusal behavior<\/li>\n<li>Guardrail robustness under adversarial prompting<\/li>\n<li>Cross-model generalization of attack patterns<\/li>\n<li>How vendors coordinate fixes without over-blocking legitimate use<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Pliny said he does not believe public release would make the world \u201cany more dangerous,\u201d but he acknowledged that others may disagree. During the disclosure period, he aims to map the full impact, measure how much extra capability the method unlocks, and help frame the issue for decision-makers.<\/p>\n<p class=\"wp-block-paragraph\">Security teams and AI product owners should treat this as an early warning, not confirmed proof. Independent validation, vendor advisories, and any coordinated patch guidance will matter more than the initial claim alone.<\/p>\n<p class=\"wp-block-paragraph\">Until labs respond or the method is documented through proper channels, organizations relying on these models should keep standard controls in place: output monitoring, least-privilege tool access, human review for high-risk workflows, and clear escalation paths for policy violations.<\/p>\n<p class=\"wp-block-paragraph\">The researcher said he looks forward to sharing the method \u201cwhen the time is right.\u201d For now, the industry\u2019s next move\u2014private testing versus public panic will shape how this story develops.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong>\u00a0Strengthen Your SOC by Accelerating Threat Detection &amp; Rapid Investigations.\u00a0-&gt;\u00a0<a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Integrate ANY.RUN With Your SOC\u00a0<\/a><strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Now<\/a><\/strong>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/jailbreak-on-top-ai-models\/\">Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/jailbreak-on-top-ai-models\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable A well-known AI red teamer claims to have developed a universal jailbreak that works against leading large language models, including heavily guarded flagships such as GPT-5.6 Sol, Claude Opus 5, and Fable. In a public post on X, Pliny the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-14586","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14586"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14586"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14586\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}