v2.1.183 improves auto mode safety by blocking destructive git and destroy commands without explicit user consent. It adds deprecation warnings for models, introduces attribution.sessionUrl to hide session links, and fixes multiple issues including terminal behavior, subagent performance, and input handling in web and tmux environments.
v2.1.183 Release Notes
Prompt injection researcher breaks Claude Code Opus 5 Auto Mode
Anthropic recently made Claude Code's auto mode the default to protect users against prompt injection attacks, but researcher Johann Rehberger has demonstrated a significant vulnerability in this safety mechanism. He identified an attack that succeeds approximately 80% of the time by tricking the agent into downloading and uncompressing a zip archive containing a malicious Python file.
Anthropic makes auto mode the default in Claude Code for Pro, Max, and Team plans
Anthropic is making auto mode the default setting for new sessions in Claude Code for Pro, Max, and Team plans starting on August 14th. This change reflects the company's confidence in the feature's ability to mitigate risks like prompt injection and data exfiltration more effectively than human review.
Claude Code v2.1.248 adds restricted mode and cross-session messaging
Claude Code v2.1.248 introduces a new `--restricted` mode that removes built-in command execution tools and ignores user settings to enhance security. The update also adds cross-session messaging capabilities between sessions on the same machine across Bedrock, Vertex, and Foundry environments.
Anthropic opens 10,000 free or discounted Claude seats for scientists
Anthropic is expanding its support for the scientific community by opening 10,000 seats for researchers to access Claude subscriptions for free or at discounted rates for one year. This initiative includes a new Claude team plan for scientists, with standard seats provided at no cost and premium seats offering five times the usage limits for $15 per month.
GLM-5.3 Flash approaches Claude Opus 4.8 on coding benchmarks
Z.ai revealed that the previously anonymously tested model ox-alpha is GLM-5.3-Flash, a 320B-parameter Mixture of Experts (MoE) model with 18B active parameters.