China's cybersecurity agency warned that Claude Code versions from April through late June contained hidden code that sent user location and identity to remote servers. Anthropic confirmed the code existed — but says it was an experiment to block unauthorized resellers and model distillation.
Five releases in four days bring auto mode to AWS Bedrock, Google Vertex, and Azure Foundry, plus terminal rendering fixes, tighter security defaults, and a new /cd shortcut.
Claude Code and Claude Cowork are now in public beta for U.S. federal, state, and local agencies, running in a FedRAMP High authorized environment with hard spending caps and tamper-evident audit logs.
Claude Code 2.1.202 ships a /config knob for controlling how large dynamic workflows grow, OpenTelemetry attributes for correlating workflow agent activity, a cleaner /workflows UI, and fixes for Remote Control drops, session slowness in multi-worktree repos, and more.
Claude Code 2.1.200 ships two notable UX changes: the default permission mode is now called Manual across all surfaces, and AskUserQuestion dialogs no longer auto-continue after a timeout. A large batch of background agent fixes ships alongside.
Claude Code 2.1.198 ships automatic commit, push, and draft PR creation for background agents, hooks for agent lifecycle events, and the general availability of Claude in Chrome.
The latest Claude Code release switches the default model to Sonnet 5, which ships a native one-million-token context window. Promotional API pricing of $2/$10 per million tokens runs through August 31.
Version 2.1.196 adds org-level default model settings, readable auto-generated session names, clickable file attachments in chat, and a 25% token reduction for /code-review. The streaming idle watchdog is now on by default.
Claude Code v2.1.195 shipped June 26 with fixes for voice dictation on macOS and for Japanese, Chinese, and Thai auto-submit, a hook matcher correction for hyphenated identifiers, a new env var for disabling mouse clicks in fullscreen, and better background agent reliability.
Claude Code v2.1.193 shipped June 25 with a new setting to route all shell commands through auto-mode classification, OpenTelemetry logging for model response text, live bash path autocomplete, and fixes for several background agent bugs.
The June 23 release adds a sandbox.credentials setting to block sandboxed commands from reading API keys and secret env vars, plus organization-level model restrictions that show a clear message when a model is off-limits.
The June 22 release adds claude mcp login/logout commands for authenticating MCP servers without the interactive menu, makes ! shell commands automatically trigger a Claude response, and adds workflow status filtering and a Skills section to the plugin tab.
Security researchers at Tenet Security showed that a public Sentry credential is enough to inject malicious instructions into AI coding agents. Claude Code, Cursor, and Codex all fell for it with an 85% success rate.
The June 19 release hardens auto mode by blocking git reset --hard, git commit --amend, terraform destroy, and other destructive commands unless you explicitly ask for them. Also adds model deprecation warnings and config improvements.
A planned June 15 change that would have moved Agent SDK and claude -p usage to a separate per-user credit pool was pulled back by Anthropic on the same day it was supposed to take effect, after significant developer pushback.
The June 15 release adds Tool(param:value) permission syntax so you can block specific models from being used by subagents, plus contextual skill loading from nested .claude/ directories.
Two Claude Code releases landed June 12: version 2.1.175 adds enforceAvailableModels, a managed setting that locks the Default model to an approved list. Version 2.1.176 closes a loophole, fixes session language generation, and resolves over a dozen Remote Control bugs.
Today's Claude Code update adds a detailed usage attribution breakdown to the VS Code /usage dialog, showing cache misses, long context sessions, subagent use, and per-skill, per-MCP token consumption over the last 24 hours or 7 days.
Anthropic shipped Claude Code 2.1.172 on June 10, adding support for sub-agents that can delegate to their own sub-agents, up to five levels deep. The update also improves AWS Bedrock region detection and adds search to the plugin marketplace.
Anthropic shipped Claude Code v2.1.169 on June 8 with 30 changes. The headliners are a --safe-mode flag for troubleshooting without customizations and a /cd command that lets you move a session to a different directory without clearing the prompt cache.
In a new conversation marking Claude Code's first year, Anthropic engineers including Boris Cherny walk through how the tool went from two Slack reactions to developers running thousands of agents, and the working habits that changed along the way: verification, routines, auto mode, and loop.
A new report from Anthropic's safety institute documents how Claude went from authoring almost none of the company's code in early 2025 to more than 80% of merged production commits by May 2026. The paper also proposes a verifiable global pause mechanism for frontier AI development.
Microsoft's Experiences + Devices division is canceling Claude Code licenses and steering engineers to GitHub Copilot CLI before the fiscal year ends. The reason: costs spiraling to $2,000 per engineer per month, and a product conflict the company can no longer ignore.
Claude Code 2.1.166, released June 6, lets you define up to three fallback models for when your primary is overloaded, adds glob support to deny rules, and hardens cross-session messaging security.
ESC
Start typing to search across tools, news articles, and reviews
No results found
Optional analytics and social embeds help us improve the site. It works fully without them.
Privacy
Privacy Settings
Choose which optional features you want to enable.
Your browser sent a global privacy opt-out signal. We respect that by default.