Fetching from the wire…
Public story · 2026-08-05 · high
AISI's guidance and four Black Hat launches landed within 48 hours, all betting on technical limits over model behavior.
Why now: The Claude Code fixes, AISI's guidance, and the Black Hat launches all landed within the same 48 hours, as of August 5, 2026.
Anthropic patched four separate bypasses in Claude Code's enforcement layers, fixed across two releases, per the project's changelog.
Anyone running Claude Code agents against repositories they don't fully trust was leaning on those layers as the security boundary. All four failed before the fixes shipped in versions 2.1.221 and 2.1.222.
Within the same 48 hours, AISI issued its own containment recommendations, and four containment-related product launches landed at Black Hat. Specifics on both aren't available yet, but the direction matches: move containment out of the model's judgment and into infrastructure the model can't touch.
Run untrusted-repo agents in a container or VM instead of a plain worktree. Scope credentials at the token level instead of handing an agent a broad key. And stop treating any guard that lives inside the same process as the agent as a real boundary. It's a suggestion the process can talk itself past, not a wall.
Each link below shares sources, entities, or timing with this story.
Go rotate a key. I'll wait. Claude Code 2.1.246, released August 25, lists this in its changelog: a fix for "telemetry and metrics requests to Anthropic carrying the API key configured for a third-party gateway (ANTHROPIC_BASE_URL); a credential is now only sent to its own hos...
Three separate Anthropic changes over about two weeks point the same direction, and none of them announced themselves as a strategy. Claude Code 2.1.238 added claude self-hosted-runner --defer-shutdown-max-min, which keeps serving attached sessions on SIGTERM, parks whatever's...
Anthropic's June changelog doubled Claude Code rate limits, raised Opus API limits, and shipped nested skills, streamlined agent teams, and tighter permissions and auto-mode review. The headroom and nested-skills support matter most if you run Claude Code heavily in automated...
SkillsMetric evaluated 2,266 skills across 16 attack types, hitting F1 of 73.4%±0.5% overall (arXiv 2608.08468). Host destruction via shell commands: 0% detection. Natural-language prompt injection: 42%. If you lint third-party skills before install, this tells you precisely w...
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
Released July 10, /doctor scans checked-in CLAUDE.md files and flags content Claude could derive by reading the codebase itself. This is the first time Anthropic has shipped tooling treating context files as a cost surface to prune rather than a document to grow. Same release...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.