---
title: "OpenAI's $38.5B loss lands, Fable 5 ban enters crisis talks"
url: https://daily.dev/posts/openai-s-38-5b-loss-lands-fable-5-ban-enters-crisis-talks-bztit76ni
source_url: https://daily.dev/posts/openai-s-38-5b-loss-lands-fable-5-ban-enters-crisis-talks-bztit76ni
type: freeform
source: "Agentic Digest"
published: 2026-06-16T04:18:43.601Z
updated: 2026-06-16T04:19:35.120Z
tags: ["security", "llm", "openai", "ai-agents", "anthropic"]
reading_time: 5
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAI's $38.5B loss lands, Fable 5 ban enters crisis talks

**[Agentic Digest](https://daily.dev/sources/agents_digest)** · 5 min read · 1 upvotes · 0 comments

## Summary

A roundup of major AI and tech news: OpenAI's audited 2025 financials reveal a $38.5B net loss (up from $5B), with $17.2B paid to Microsoft. Anthropic's senior staff are in Commerce Department crisis talks over the Fable 5/Mythos 5 export ban, while a fine-tuned model on Fable 5 reasoning traces has already spread widely. Salesforce is acquiring Fin (formerly Intercom) for $3.6B to strengthen its Agentforce AI customer service platform. A patched one-click data theft vulnerability (SearchLeak/CVE-2026-42824) in Microsoft 365 Copilot chained prompt injection, an HTML sanitizer race condition, and a Bing SSRF. Notable items include Zhipu's GLM-5.2 open-source release, active exploitation of a Langflow RCE, Cohere's North Mini Code model, and new AI agent identity startup NewCore raising $66M.

## Content

**TLDR:** OpenAI's audited financials show a $38.5 billion net loss in 2025, up from $5 billion the year before, with $17.2 billion paid to Microsoft alone. The Fable 5 situation is still moving: Anthropic's senior technical staff are in Commerce Department meetings today, 100+ cybersecurity experts have signed an open letter calling the ban counterproductive, and a gemma-4-12B fine-tuned on Fable 5 reasoning traces has already been downloaded 20K+ times. Separately, Salesforce is acquiring Fin (formerly Intercom) for $3.6 billion to bolster Agentforce, and a critical one-click data theft vulnerability in Microsoft 365 Copilot has been patched.

---

## OpenAI lost $38.5B in 2025, paid Microsoft $17.2B

Audited financials verified by the Financial Times show OpenAI's net loss grew nearly 8x year-over-year, from $5.09B in 2024 to $38.5B in 2025. Total costs hit $34B, driven by $19.18B in R&D and $7.5B in cost of revenue. Microsoft received $17.2B in total expenses, with $10.59B attributed to R&D — almost certainly model training costs. A $41.55B charge tied to the nonprofit-to-for-profit conversion pushed the gross loss to $60.35B before adjustments. The company held just over $50B in assets at year-end, roughly half in cash. [Read more](https://app.daily.dev/posts/KCXU4bwml)

## Anthropic in crisis talks with Commerce over Fable 5 ban

Anthropic's senior technical staff are meeting with US Commerce Department officials today to resolve the suspension of Fable 5 and Mythos 5. The ban was triggered after Amazon researchers flagged a jailbreak — but multiple security researchers, including Katie Moussouris, have reviewed the underlying research and called the bypass trivial, arguing it should never have triggered export controls. Over 100 cybersecurity experts have signed an open letter saying the ban disarms defenders while adversaries use open-source alternatives. Prediction markets put 68-71% odds on the ban reversing before July 1. Meanwhile, a gemma-4-12B model fine-tuned on Fable 5 reasoning traces has been downloaded 20K+ times — the API is dead but the knowledge is already in the wild. [Read more](https://app.daily.dev/feed-by-ids?id=38N9myGGx&id=9hgCpPXLZ&id=FmZW9X8yw&id=mLMY6NC1i&id=BP57KSC2b&id=qUZGFtovj)

## Salesforce acquires Fin for $3.6B to compete in AI customer service

Salesforce is buying Fin, formerly Intercom, for $3.6 billion. Fin's AI agent resolves 76% of customer queries without human intervention using its proprietary Apex model, and brings 30,000+ business customers. The deal gives Salesforce a fast-deploy packaged support agent alongside its customizable Agentforce platform, and reduces reliance on OpenAI and Anthropic for model access. Expected to close in Q4 of Salesforce's fiscal 2027. [Read more](https://app.daily.dev/feed-by-ids?id=EIuDqrCLY&id=VHVUccfP6)

## SearchLeak: one-click data theft via Microsoft 365 Copilot, now patched

Varonis disclosed a three-stage attack chain called SearchLeak (CVE-2026-42824) that let an attacker exfiltrate emails, MFA tokens, calendar data, and SharePoint files with a single click on a crafted Microsoft link. The attack chains a prompt injection via the search query parameter, an HTML sanitizer race condition, and a Bing SSRF that bypasses Content Security Policy. Microsoft patched it server-side — no user action required. This is the second similar Varonis disclosure against Copilot, following the Reprompt attack, and mirrors the zero-click EchoLeak vulnerability. [Read more](https://app.daily.dev/feed-by-ids?id=wRsuwvRWG&id=L731prZby&id=FfQgDzKcX)

---

## Also notable

- **Zhipu stock surged 48% after GLM-5.2 open-source launch timed to Fable ban:** Zhipu's Hong Kong-listed stock jumped up to 48% after it released GLM-5.2 as open-source with no usage restrictions, explicitly timed to the US forcing Anthropic offline — JPMorgan raised its price target and Bank of America initiated with a buy rating, with GLM-5.2 featuring a one-million-token context window and early community benchmarks suggesting performance close to Claude Opus 4.7 on coding tasks. [Read more](https://app.daily.dev/posts/hJBfX6hHK)
- **Langflow RCE under active exploitation, 7,000 instances still exposed:** CVE-2026-5027, a path traversal flaw in Langflow's file upload endpoint enabling full remote code execution, is under active attack by Iranian state-sponsored group MuddyWater despite a patch shipping over two months ago — auto-login is enabled by default, requiring no credentials, and roughly 7,000 internet-exposed instances remain unpatched (fix: upgrade to 1.9.0 or later). [Read more](https://app.daily.dev/posts/jzjaNnQnB)
- **Cohere releases North Mini Code, a 30B MoE coding model under Apache 2.0:** Cohere's first coding model has 3B active parameters, runs on a single H100, and is Apache 2.0 licensed — targeting teams that want self-hostable agentic coding without depending on API providers that can be switched off by government order. [Read more](https://app.daily.dev/posts/bEsZCIpk8)
- **NewCore raises $66M at $300M valuation to manage AI agent identities:** The Tel Aviv/SF startup emerged from stealth to issue cryptographic identities to AI agents, scope their permissions, and log their actions — positioning against Okta and Microsoft Entra, with fewer than 10 customers and plans to start charging this summer. [Read more](https://app.daily.dev/feed-by-ids?id=STvHoFnPU&id=qhzAozCFU)
- **Kimi K2.7-Code ships with 1T-parameter MoE, 30% fewer reasoning tokens, at $0.95/M input:** Moonshot AI's open-source coding model uses 32B active parameters from a 1T total, scores 81.1 on MCP Mark Verified for agentic tool-use, and teams on K2.6 can migrate by swapping the model ID in existing vLLM or SGLang infrastructure — though all benchmarks so far are Moonshot proprietary with no independent SWE-bench results yet. [Read more](https://app.daily.dev/posts/RPLl6qhkm)

---

Tags: [#security](https://daily.dev/tags/security), [#llm](https://daily.dev/tags/llm), [#openai](https://daily.dev/tags/openai), [#ai-agents](https://daily.dev/tags/ai-agents), [#anthropic](https://daily.dev/tags/anthropic)

[View this post on daily.dev](https://daily.dev/posts/openai-s-38-5b-loss-lands-fable-5-ban-enters-crisis-talks-bztit76ni)
