---
title: "Fable 5 is fully back, GitHub Models shuts down July 30"
url: https://daily.dev/posts/fable-5-is-fully-back-github-models-shuts-down-july-30-xyjn072iz
source_url: https://daily.dev/posts/fable-5-is-fully-back-github-models-shuts-down-july-30-xyjn072iz
type: freeform
source: "Agentic Digest"
published: 2026-07-02T04:18:55.178Z
updated: 2026-07-02T04:19:12.091Z
tags: ["security", "claude", "ai-coding"]
reading_time: 5
upvotes: 5
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Fable 5 is fully back, GitHub Models shuts down July 30

**[Agentic Digest](https://daily.dev/sources/agents_digest)** · 5 min read · 5 upvotes · 0 comments

## Summary

Fable 5 returned globally on July 1 after US export controls were lifted, with a new safety classifier blocking the reported jailbreak in 99%+ of cases — though Anthropic now mandates 30-day data retention for all traffic, including customers who previously had zero-retention agreements. GitHub Models is being fully retired on July 30, affecting the playground, model catalog, inference API, and BYOK endpoints. Together AI closed an $800M Series C at an $8.3B valuation, with Cursor and Cognition among its customers. Two critical RCE vulnerabilities in Cursor IDE were patched in Cursor 3.0, and a Langflow RCE is being actively exploited in the wild to deploy cryptominers.

## Content

**TLDR:** Fable 5 returned globally on July 1 after US export controls were lifted, with a new safety classifier blocking the reported jailbreak in 99%+ of cases — though Anthropic now mandates 30-day data retention for all traffic, including customers who previously had zero-retention agreements. GitHub Models is being fully retired on July 30, affecting the playground, model catalog, inference API, and BYOK endpoints. Together AI closed an $800M Series C at an $8.3B valuation, with Cursor and Cognition among its customers. Two critical RCE vulnerabilities in Cursor IDE were patched in Cursor 3.0, and a Langflow RCE is being actively exploited in the wild to deploy cryptominers.

---

## Fable 5 fully restored with new safety classifier and mandatory data retention

Anthropic redeployed Fable 5 globally on July 1 after the US Department of Commerce lifted export controls imposed on June 12. The controls were triggered by a jailbreak that exposed cybersecurity capabilities; Anthropic's new safety classifier blocks the technique in over 99% of cases, though with more false positives on routine coding tasks. The bigger operational change: Anthropic now mandates 30-day data retention for all traffic, even for customers who previously had zero-retention agreements. Fable 5 is live again in Cursor, Devin, and other tools — but the data terms are the thing to read carefully before assuming your previous contract still applies. [Read more](https://daily.dev/feed-by-ids?id=tYIZsGbqf&id=OD3zQPOkj&id=DijFVohdR&id=UP74w7org&id=MzlAsMGmn&id=NcEhit0Bc)

## GitHub Models retires July 30, users directed to Azure AI Foundry

GitHub Models is shutting down completely on July 30, 2026 — playground, model catalog, inference API, and BYOK endpoints all go dark. Scheduled brownouts on July 16 and July 23 will serve as advance warnings. Existing users are being pushed to Azure AI Foundry for model access or GitHub Copilot for AI workflows within GitHub. If you have anything built on the GitHub Models inference API, you have less than four weeks to migrate. [Read more](https://daily.dev/posts/bz8saAvyW)

## Together AI raises $800M Series C at $8.3B valuation

Together AI closed an $800M Series C led by Aramco Ventures, with Nvidia, General Catalyst, and Vista Equity also participating. The company reports over $1.15B in annual bookings and claims its inference optimization software can cut model running costs by up to 80% versus standard cloud pricing. Customers include Cursor and Cognition. The raise reflects a broader shift: as open-weight models like DeepSeek and Qwen mature, the infrastructure layer running them is attracting serious capital — and Middle Eastern sovereign funds are increasingly targeting compute rather than model labs. [Read more](https://daily.dev/feed-by-ids?id=UYTHhBNT5&id=nbdgfTVoz&id=x86VO0l0w)

## Langflow RCE actively exploited, Cursor IDE sandbox bypass patched

A critical unauthenticated RCE in Langflow (CVE-2026-33017, CVSS 9.8) is being actively exploited to deploy cryptominers across roughly 7,000 exposed servers. Attackers send a single HTTP POST with no auth, then install a Go-based miner that kills rivals, disables AppArmor and iptables, and harvests .env files and API keys. Upgrade to Langflow 1.9.0 immediately and rotate all credentials on exposed instances. Separately, Cato Networks disclosed two Cursor IDE sandbox bypass flaws (CVE-2026-50548 and CVE-2026-50549) that allowed prompt-injection-triggered RCE — both patched in Cursor 3.0 back in April, but the disclosure confirms prompt injection as a real RCE vector in agentic coding tools, not a theoretical one. [Read more](https://daily.dev/feed-by-ids?id=ETL1OhLb0&id=FnfY3VrJ6)

---

## Also notable

- **Kimi K2.7 Code is the first open-weight model in GitHub Copilot's model picker:** Moonshot AI's Kimi K2.7 Code is now generally available in Copilot across VS Code, JetBrains, Xcode, and mobile — off by default for Business and Enterprise plans, requiring explicit admin enablement. [Read more](https://daily.dev/posts/fQIa798Tf)
- **Godot bans autonomous AI agent contributions, auto-bans violators:** The Godot Foundation updated its contribution policy to prohibit AI-agent-submitted PRs and vibe-coded code, citing reviewer burnout from a surge in AI-generated submissions and the inability of LLMs to take responsibility for their code or become future maintainers. [Read more](https://daily.dev/feed-by-ids?id=Ig5XpIsqR&id=dECENQBsP&id=FWP3RSKcR)
- **Apple's Safari MCP server exposes 17 browser tools to coding agents:** Safari Technology Preview 247 ships an MCP server that lets Claude, Codex, or any MCP-compatible client autonomously inspect the DOM, capture screenshots, read console logs, and monitor network requests — running entirely locally with no access to personal Safari data. [Read more](https://daily.dev/posts/CxmMLJUMW)
- **Cloudflare launches Pay Per Use and Monetization Gateway for AI-era content economics:** Cloudflare announced Pay Per Use (publishers paid when content appears in AI answers, not just when crawled), a Monetization Gateway for charging AI agents per request via stablecoin payments using the x402 protocol, and a default block on AI training crawlers for new free-tier sites starting September 15. [Read more](https://daily.dev/feed-by-ids?id=I5yWynW2Y&id=aYLB3tUzy&id=VduMWudVn&id=y7P26qDQ7)
- **Devin Fusion cuts Fable-level agentic coding costs by 35% with a sidekick model:** Cognition previewed Devin Fusion, a hybrid-model harness that routes grunt work to a smaller sidekick model while reserving the frontier model for planning — reporting 35% cost reduction versus running Fable 5 end-to-end on all tokens. [Read more](https://daily.dev/posts/41cbl9lz0)

---

Tags: [#security](https://daily.dev/tags/security), [#claude](https://daily.dev/tags/claude), [#ai-coding](https://daily.dev/tags/ai-coding)

[View this post on daily.dev](https://daily.dev/posts/fable-5-is-fully-back-github-models-shuts-down-july-30-xyjn072iz)
