AI red teamer Pliny the Liberator has publicly claimed to have developed a universal jailbreak that works across several leading large language models, including GPT-5.6 Sol, Claude Opus 5, and Fable. The reported technique is said to be effective across multiple tested models and categories, and may be difficult or impossible to fully patch because of how it operates, although the claim has not been independently validated.
Pliny is withholding the full method while seeking a responsible disclosure window so AI labs, red teamers, safety researchers, and policymakers can assess the issue privately before wider انتشار. If confirmed, the jailbreak would underscore persistent weaknesses in model safety training, refusal behavior, guardrail robustness, and resistance to adversarial prompting. Organizations using these models were advised to maintain standard safeguards, including output monitoring, least-privilege tool access, human review for high-risk workflows, and escalation paths for policy violations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Pliny said he is withholding the full jailbreak technique and is seeking a responsible disclosure window so AI labs, red teamers, safety researchers, and policymakers can privately assess the issue before wider spread. The reporting frames this as an early warning rather than a confirmed, fully disclosed exploit.
AI red teamer Pliny the Liberator publicly claimed to have developed a universal jailbreak affecting multiple leading large language models, including GPT-5.6 Sol, Claude Opus 5, and Fable. The reports say the claim has not yet been independently validated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.