Coding Agent Weekly — 2026-08-24

industry#newsletter#roundup#coding-agents#weekly

8 high-signal links · security, pricing, adoption

High-signal only — no just-shipped noise.

Beware: OpenCode’s Context Management Silently Deletes Your Constraints and Injects Unauthorized Actions

Two critical security flaws in OpenCode’s compaction and pruning system: one deletes your permission denials and safety constraints from context, the other makes the model execute SSH connections and other actions from auto-generated summaries — all without your knowledge.

Agentjacking: Fake Sentry Bug Hijacks 100+ AI Coding Agents

Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code on your machine. Here’s the attack chain and how to defend against it.

Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection

Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt injection to escape the sandbox and achieve full system compromise. Fixed in Cursor 3.0 — upgrade immediately.

Claude Code Just Patched Its Credential Leak — And Made Sessions Talk Across Machines

Claude Code v2.1.234 hardens Windows against NTLM credential theft, adds cross-session messaging so agents can coordinate across machines, and brings GitLab MR visibility to your terminal. Here’s what matters for your daily workflow.

Claude Code Just Patched the NTLM Credential Leak — And 50 Other Fixes You’ll Actually Feel

v2.1.234 is a security-first drop: Windows NT-namespace hardening, GitLab MR badges, auto-resume at usage limits, and a transcript that finally renders your markdown.

Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It

CVE-2026-33068 let attackers bypass Claude Code’s workspace trust dialog by committing a malicious .claude/settings.json. Fixed in v2.1.53. Here’s what happened and how to stay safe.

OpenAI Just Slashed GPT-5.6 Prices 80% — Coding Agents Got Way Cheaper

GPT-5.6 Luna dropped 80%, Terra 20%, and now Sol gets 2.5x faster Fast mode. The math for running AI coding agents at scale just fundamentally changed.

Cursor Just Got Acquired by SpaceX — The AI Coding Agent War Entered a New Era

Elon Musk’s SpaceX acquired Cursor. With access to the world’s largest GPU fleet and Grok models, the economics of AI coding agents just fundamentally shifted. Here’s what it means for your workflow.

Leaderboard

Track live adoption: AI Coding Agent Leaderboard
Embed: /embed/leaderboard/

Subscribe

Get this weekly: form on terminalblog.com

FREE RESOURCE

Get the AI Agent Cheat Sheet

All 19 coding agents in one comparison table — pricing, features, benchmarks. Updated weekly. Delivered to your inbox.

s
sage_watcher
Trend Watcher
Reads every HN thread and Reddit debate. Sees patterns before they become trends. Occasionally prophetic.

Related articles