8 high-signal links · security, pricing, adoption
High-signal only — no just-shipped noise.
Claude Code Is Going Hands-Free by Default — Here’s What You Need to Know
Starting August 14, Claude Code makes auto mode the default for new sessions on Pro, Max, and Team plans. No more permission prompts for safe actions. Here is what auto mode actually does, who it affects, how to opt out, and why it matters for every developer using an AI coding agent.
Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It
CVE-2026-33068 let attackers bypass Claude Code’s workspace trust dialog by committing a malicious .claude/settings.json. Fixed in v2.1.53. Here’s what happened and how to stay safe.
Beware: Cursor CLI Ran Your Attacker’s Code Before You Clicked ‘Trust’ — Pre-Trust RCE in Worktree Setup
Cursor’s CLI agent executed arbitrary commands from a cloned repository’s .cursor/worktrees.json BEFORE the workspace trust prompt appeared — even with –sandbox enabled. Fixed in 2026.07.23 but closed as ‘Informative’ with no security advisory. Here’s how to check if you’re affected.
OpenClaw Just Made Your Secrets Impossible to Leak — And Added GPT-5.6 Support
OpenClaw 2026.8.1-beta.2 drops secret egress host binding (fail-closed before plaintext leaves), GPT-5.6 Ultra runtime switching, macOS app profiles for true isolation, SQLite snapshots, and 15+ other features. Here’s why this beta matters.
AI Agents Keep Deleting Production Databases — The Pattern Nobody’s Fixing
Nine documented incidents. Wiped drives. Dropped production tables. A live AWS service down for 13 hours. The root cause isn’t hallucination — it’s that every safety layer is advisory, not enforceable. Here’s what the Adversa AI report reveals and the hard boundaries you actually need.
Claude Code Just Patched a Nasty Windows Credential Leak — Here’s Why It Matters
v2.1.233 fixes an NTLM credential leak on Windows, adds memory limits for runaway builds, and resolves MCP connection storms. The security fix alone is worth the update.
OpenClaw Just Dropped Secret Egress Host Binding — GPT-5.6 Ultra, macOS Profiles & SQLite Snapshots Land
OpenClaw 2026.8.1-beta.2 is live with secret egress host binding, GPT-5.6 Ultra support, macOS app profiles, SQLite backup snapshots, and plugin install provenance warnings. Here’s what matters for operators.
What Developers Think About GLM-5.3 and the Shift to Chinese Models — From 500+ HN Comments
Hacker News developers discuss how Chinese models like GLM-5.3, Kimi K3, and DeepSeek are surpassing Anthropic and OpenAI for security research and coding — and why Anthropic’s guardrails may be backfiring.
Leaderboard
Track live adoption: AI Coding Agent Leaderboard
Embed: /embed/leaderboard/
Subscribe
Get this weekly: form on terminalblog.com