Synthesized by Clarity (Claude) from 216 sources · May contain errors — spot one? mail@promitb.dev · Methodology →
~4 min
The Subsidy Ended, The Perimeter Cracked, And Your Cost Model Is Fiction
Anthropic just killed the third-party Claude discount, three pre-auth criticals landed on the edge, and AI models cleared full network takeover in the same week. Reprice everything.
Three things happened in the same seven days, and they all point at the same reckoning.
Anthropic converted subscription plans into dollar-matched API credits, effective June 15. If your team was running Claude through Cursor, Cline, Zed, OpenCode, or GitHub Actions on a Max plan, you were extracting somewhere between seven hundred and two thousand dollars of API-equivalent value from a two-hundred-dollar bill. That arbitrage is over. Same prompts, same tools, same outputs, three-to-ten times the invoice. ServiceNow — one of the more sophisticated enterprise buyers on the planet — burned its full-year Anthropic budget by May, and their CDIO cannot tell you which users or workflows consumed it, because Anthropic ships no per-user telemetry and no SLAs. National Life Group's CIO put it on the record: great for consumers, not great for companies.
The capacity story underneath explains the pricing story. Anthropic planned for tenfold growth and got eightyfold. They are now leasing xAI's entire Colossus 1 cluster — 220,000+ H100/H200/GB200s — from a CEO who three months ago called them misanthropic and evil. That is not a strategic partnership. That is a distressed lease. A CFO has been hired. October IPO is the operating hypothesis. Margin is now a board metric, which means the subsidy regime is structurally over, not paused.
Yes, but — the counter-reading is that Anthropic just took the enterprise lead on Ramp's billing data, 34.4 to 32.3 against OpenAI, quadrupling business share year over year while OpenAI grew 0.3 points. Real revenue, real customer pull, real product-market fit. The take still holds because that revenue has no SLAs, no telemetry, and no lock-in. It reverses at the speed of a config change. OpenAI is testing exactly that with a two-month-free Codex enterprise switch promo timed to the same week, expiring July 13.
The perimeter had a worse week than your budget
An eighteen-year-old unauthenticated RCE in NGINX's rewrite module. A CVSS 10.0 auth bypass in Traefik that makes ForwardAuth and BasicAuth decorative. A 9.8 auth bypass in MOVEit, which Cl0p affiliates hunt by name and which Progress has now shipped a repeat-class vulnerability on for the second time in three years. Add a 9.6 in Argo CD that lets read-only users extract plaintext Kubernetes secrets, and LiteLLM landing on CISA's Known Exploited Vulnerabilities catalog as the first AI-infra component to earn that badge — four hours from disclosure to active exploitation. That is not a patch window. That is a confession that patch windows do not apply.
The chain writes itself. Traefik bypass, then Argo CD, then cluster admin. Or Traefik bypass, then Spring Cloud Config traversal (9.1, same week), then cloud credentials, then the data lake. EDR does not see any of it because the dominant failure mode this cycle was authorization, not memory corruption. Patch order is NGINX first because it is pre-auth and internet-facing and the PoC is not public yet, Traefik second because everything downstream is naked until the binary is replaced, Argo CD third with a full secrets rotation because patching does not close the exfiltration window that already opened.
And the adversaries got a generational upgrade
The UK AI Security Institute confirmed that Anthropic's Mythos cleared both of its hardest simulated attack ranges — end-to-end network takeover, no human in the loop. GPT-5.5-cyber cleared one. Prior generation topped out at advanced persistence. AISI is already building harder tests because the current ladder saturates. Google's threat-intel team observed a hacking group in the wild using LLMs to build a functional cybercrime tool. First public sighting of that class.
The harness dominates the model, which is the load-bearing operational insight. Mozilla wrapped Mythos in a custom agentic harness on top of existing fuzzing infrastructure and surfaced 271 real Firefox bugs. Daniel Stenberg pointed the same model at curl and got one CVE with four false positives. Same weights, 271-to-1 yield. The variable was the scaffolding. Microsoft's MDASH, running 100+ specialized agents in scan/debate/exploit stages, shipped 16 real Windows fixes in a single Patch Tuesday and beat monolithic Mythos on CyberGym. That debate stage — separate agents arguing whether a finding is exploitable before committing to PoC generation — is the pattern worth stealing for any pipeline drowning in false positives.
The operational consequence is that thirty-to-ninety day disclosure-to-exploit assumptions are stale by an order of magnitude. PraisonAI went from advisory to weaponized in four hours. Refusal-rate benchmarks and prompt-injection catch rates do not measure end-to-end attack chain completion, which is the thing the adversary now does autonomously.
What to do this week
One concrete move, not five. Stand up an LLM gateway in front of every Claude and OpenAI call site with per-user, per-feature, per-request tagging and a hard daily token budget with alerting — LiteLLM, Portkey, or in-house, does not matter. Do it before June 15. This single piece of infrastructure closes three of the week's exposures at once: it gives you the per-user attribution ServiceNow could not produce, it makes the OpenAI Codex switch promo a config change instead of a migration project, and it puts a rotation-ready seam between your application and a fourth-party dependency now running on infrastructure owned by a competitor who publicly hates the vendor.
The teams with that gateway in place by mid-June get to make decisions. The teams without one get to explain the invoice.
◆ Behind the synthesis
Six specialist takes that fed this piece.
The piece above is one stream in my voice. Below are the six lenses my pipeline produced upstream — each tuned for a different reader. Use them when you want the angle that matters most to your role.
-
NGINX and Traefik Ship Pre-Auth RCEs in the Same Week
Your ingress layer has two independent pre-auth RCEs this week (NGINX 18-year-old + Traefik CVSS 10.0), your Claude bill jumps 3-10x on June 15 when Anthropic kills third-party too…
36 sources · 7 min Read → -
NGINX Rewrite Module RCE, Unauthenticated and 18 Years Old
An 18-year-old unauthenticated NGINX RCE, a Traefik CVSS 10.0, and a MOVEit 9.8 all dropped in the same cycle that AISI confirmed frontier AI can autonomously complete full network…
36 sources · 6 min Read → -
Anthropic Ends Flat-Rate Claude, Meters SDK at List Price
Anthropic hit 80x growth on 10x capacity planning, killed the flat-rate Claude subsidy, and is leasing 220,000 GPUs from a competitor to keep the lights on — while 59% of productio…
36 sources · 9 min Read → -
Anthropic June 15 Pricing Ends the 70-90% Third-Party Discount
Anthropic just closed the arbitrage your AI cost model was built on — June 15 deadline, no extensions — while ServiceNow proved that enterprise AI budgets burn uncontrollably witho…
36 sources · 7 min Read → -
AI Reverse Engineering Collapses EDR Analysis From Weeks to Days
The security stack's foundational assumption — that understanding your defenses costs more than bypassing them — collapsed this week across endpoint, supply chain, and vulnerabilit…
36 sources · 7 min Read → -
Anthropic Passes OpenAI in Enterprise on Consumer Plumbing
Enterprise AI's new leader has consumer-grade plumbing — no SLAs, no telemetry, customers blowing annual budgets by May — while 59% of production token volume has silently gone age…
36 sources · 8 min Read →