Maybe I could have been clearer in my original post although that’s why I did qualify my comments with “For most practical purposes it still is the best cipher.” Even if AES-128 takes billions instead of trillions years to break, I still consider that sufficient for my purposes.

Similarly I consider that the cipher is ‘broken’ because the number of combinations can be reduced (disregarding impractical amounts of time, money, resources etc.). The biclique attack is only one such method, there are others.

An extract from an academic textbook if anyone else is reading this and is interested: