Topic · 23 stories
Claude Code: updates, bugs and security news
In short
Claude Code is Anthropic's agentic coding tool: it reads a project, writes and edits code, runs terminal commands and tests, and opens pull requests instead of only suggesting snippets. Since 14 August 2026 it runs in Auto Mode by default on Pro, Max and Team plans, with no manual approval at every step. That speeds up work, but in 2026 researchers showed several ways to take over a developer's machine through a repository, a plugin or documentation.
What is Claude Code
Claude Code is Anthropic’s agentic coding tool: you give it a goal, and it reads the project, writes and edits code, runs commands in the terminal and runs tests. In newer versions it also opens pull requests. The difference from an assistant that only suggests snippets is basic: Claude Code acts on the developer’s computer, with the developer’s access to files, shell and secrets. Most of its capabilities and most of its security problems, described below, follow from that.
Two 2026 examples show the range. Google DeepMind developer Ammaar Reshi used Claude Code with Fable 5 to port Command & Conquer: Generals Zero Hour to iPhone and iPad. The first build took about 40 minutes, and the game runs natively on ARM64, with DirectX 8 translated to Apple’s Metal API. Reshi used up his whole Claude Max quota in two days. Another user unlocked the BIOS of an HP 15-dw1036ne laptop, bypassing RSA-2048 signature checks and exposing 55 hidden settings.
How does Claude Code work
Claude Code works as an agent that reads your files, picks a step, runs it with your permissions, checks the result and repeats. Anthropic describes this loop in its guide to how Claude Code works. The biggest change of 2026 is how much of that loop runs without you.
Auto Mode. From 14 August Auto Mode is the default on Pro, Max and Team; Enterprise customers must turn it on. The agent no longer asks before every command. A classifier checks whether an action is dangerous or irreversible and asks a human only then. Anthropic cites a test with 1,053 paid testers: human reviewers caught only 13.6 percent of dangerous commands, the Auto Mode classifier 89 percent. Teams in Auto Mode produced about 25 percent more pull requests. An independent audit by Trajectory Labs ran 72 attack scenarios ten times each, and none of the 720 attempts succeeded against Claude’s current models in Auto Mode. Anthropic still recommends human review for high-stakes changes to production infrastructure.
Built-in browser. In July Claude Code got a browser that reads, clicks and types on external sites, including documentation and issue trackers. It runs on a clean profile with no saved logins, classifiers screen write actions, and Claude will not buy anything, create accounts or bypass CAPTCHAs without consent. Organizations can restrict it to an allowlist or disable it.
Parallel threads. In September Anthropic rebuilt Projects around parallel agent threads. You describe a goal, a coordinator splits the work into separate cloud sessions, and each thread can run tests and open pull requests. It is a beta for select Pro and Max subscribers; Team and Enterprise come later.
Other models. Claude Code is no longer tied to Claude models. DeepSeek can be plugged in without a proxy through an Anthropic-compatible endpoint, with billing from a DeepSeek balance. DeepSeek Flash costs $0.15 per million input tokens and $0.60 output off-peak, which the source puts at roughly 7-20x cheaper than Claude Sonnet 5.
How to install, use and update Claude Code
You install Claude Code with one command in a terminal. According to Anthropic’s docs (as of 10 October 2026), on macOS, Linux and WSL it is curl -fsSL https://claude.ai/install.sh | bash. On Windows PowerShell it is irm https://claude.ai/install.ps1 | iex. Homebrew (brew install --cask claude-code), WinGet (winget install Anthropic.ClaudeCode), apt, dnf, apk and npm work too. Requirements: macOS 13 or newer, Windows 10 1809 or newer, Ubuntu 20.04+, Debian 10+ or Alpine 3.19+, 4 GB of RAM and an internet connection. Details are in Anthropic’s official quickstart guide and its advanced setup page.
To use it, open a terminal in your project folder and run claude. On first launch you sign in with a Pro, Max, Team or Enterprise account, a Claude Console account or a supported cloud provider. Then you describe the task in plain language, for example “explain the folder structure” or “fix the bug where users can submit empty forms”. Useful commands: /help lists commands, /resume continues an old conversation, claude -p "query" runs a single query and exits, claude -c continues the latest conversation, and Shift+Tab switches the permission mode. The product also runs in VS Code and JetBrains, a desktop app, a browser at claude.ai/code and mobile apps, according to the Claude Code product page.
To update, run claude update. Native installs also check for updates on startup and install them in the background. Homebrew, WinGet, apt, dnf and apk installs do not update themselves: use brew upgrade claude-code, winget upgrade Anthropic.ClaudeCode or your system’s normal upgrade. claude doctor shows installation health. This matters for security: Plugin4Shell is fixed only from version 2.1.179.
How much does Claude Code cost and is it free
Claude Code is not free: the free Claude plan does not include it, and it costs from 20 USD a month on a paid plan. Prices from Anthropic’s pricing page (as of 10 October 2026, in US dollars):
| Plan | Price | Claude Code |
|---|---|---|
| Free | 0 | not included |
| Pro | 20 per month, or 17 per month billed annually (200 up front) | included, shared plan limits |
| Max 5x | 100 per month (monthly billing only) | included, 5x Pro usage per five-hour session, 100 in API credits |
| Max 20x | 200 per month (monthly billing only) | included, 20x Pro usage per five-hour session, 200 in API credits |
| Team, standard seat | 25 per month, or 20 billed annually | included, more usage than Pro |
| Team, premium seat | 125 per month, or 100 billed annually | included, 5x a standard seat |
| Enterprise | 20 per seat per month billed annually, plus usage at API rates | included, cost scales with model and task |
Team covers 2 to 150 seats and includes up to 500 per month in pooled API credits. Two cheaper routes exist: sign in with a Claude Console account and pay API rates for the tokens you use, or run Claude Code on DeepSeek models and pay DeepSeek.
Every plan has limits. Anthropic announced a permanent 25 percent increase in weekly limits from 14 September for Pro, Max, Team and Enterprise. A temporary 50 percent boost was active at the time, so the real change is a 17 percent cut.
Companies feel it on the invoice. Uber’s CTO said the company’s 2026 AI budget was gone by April after Claude Code reached 5,000 engineers. On 2 July Anthropic gave Claude Enterprise model-level entitlements, an analytics dashboard and spend alerts at 75 and 90 percent of limits, which warn but do not stop spending.
Is Claude Code safe
Not unconditionally: in 2026 researchers repeatedly took over a developer’s machine through Claude Code by planting instructions in a repository, plugin or documentation. The shared cause is that the agent trusts text it reads and has permission to act on it. This is the pattern behind prompt injection and AI coding agents security.
Reverse shell from a DNS record. Mozilla’s 0din team took over a developer machine through a repository with no malicious code. A Markdown setup guide led Claude Code to run a command that fetched a base64 payload from a DNS TXT record controlled by the attacker, which opened a reverse shell. Every step looked harmless, so security tools missed it.
Friendly Fire. The AI Now Institute showed that prompt injections in documentation made agents run a malicious binary when a user in auto mode asked for a security assessment of the repository. Claude Code and OpenAI Codex were vulnerable, as were all four models tested, including Sonnet 5 and Opus 4.8. Salt Security counts it as the latest of four such attacks in two months, after GitLost, Agentjacking and TrustFall.
Malicious pull request and .mcp.json. Immersive Labs showed that a malicious pull request can execute code in a trusted repository. Claude Code reads .mcp.json from the project root at startup and runs the commands defined there without asking. Trust granted once covers every branch later checked out into the folder. Anthropic’s bug bounty ruled this working as designed.
Plugin4Shell. Air Security disclosed a zero-click flaw in Claude Code, Codex, GitHub Copilot and Gemini CLI. Agents pin plugins to a 40-character commit hash but never verify what they receive, and git prefers a branch over an object when a name matches both. An attacker names a branch after the hash. Anthropic fixed it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0. Microsoft shipped no fix for GitHub Copilot, and Google will not patch Gemini CLI because it is retiring it. No CVE had been assigned as of 18 September, with no sign of real-world exploitation.
Infected repositories. Microsoft took down more than 70 of its GitHub repositories after attackers planted credential-stealing malware that triggered when the code was opened in Claude Code or Gemini CLI. It is a supply chain attack aimed at agent users.
Attackers use the tool too. Hunt.io found an open server of suspected China-linked operators who used Claude Code with DeepSeek to breach government systems in four countries. Claude Code version 2.1.165 handled execution and phishing pages, DeepSeek wrote scripts, and a CLAUDE.md file told the agent to build and test cloned login pages. More in state-backed hackers using AI.
Did Claude Code have a backdoor in China
Claude Code had hidden code that flagged users in China, which Anthropic calls an anti-abuse experiment and China’s vulnerability database calls a backdoor. A Reddit user found that since version 2.1.91, released 2 April, Claude Code checked the system timezone for Asia/Shanghai or Asia/Urumqi and scanned proxy URLs for Chinese domains and AI labs. The result went out through tiny changes to the system prompt, a different date format and a swapped apostrophe in “Today’s date is”. Anthropic engineer Thariq Shihipar called it an experiment against unauthorized resellers and distillation and said it was removed on 1 July.
The affair continued. Alibaba banned its employees from using Claude Code from 10 July. China’s National Vulnerability Database warned about versions 2.1.91 to 2.1.196 and advised uninstalling them or upgrading. Anthropic disputes the word backdoor and notes that Claude is not permitted for use in China.
What it means for you
- Treat every foreign repository, plugin and documentation page as possible instructions for the agent. Before using Auto Mode, review
.mcp.json, the.claude/folder andsettings.json, especially after switching to someone else’s branch. - Update Claude Code right after releases. Plugin4Shell is closed only from 2.1.179.
- Do not run an agent with access to production secrets on code you do not know. The agent’s permissions are your permissions.
- In a company, set cost alerts and an allowlist for the agent’s browser, and decide whether Auto Mode is on for Enterprise.
- Check prices against the official page before budgeting: weekly limits changed in September.
Still open: when parallel threads reach Team and Enterprise, whether Plugin4Shell gets a CVE number, and whether Anthropic will change its position on running .mcp.json without asking.
Key facts
- Claude Code can run on DeepSeek models through an Anthropic-compatible endpoint, with no proxy. Billing then comes from a DeepSeek balance instead of an Anthropic subscription. (source)
- Plugin4Shell, a zero-click remote code execution flaw, hit four coding agents. Anthropic fixed Claude Code in 2.1.179. No CVE had been assigned as of 18 September. (source)
- Anthropic rebuilt Projects around parallel agent threads, each a separate cloud session that can run tests and open pull requests. Beta for select Pro and Max subscribers. (source)
- A limit change cuts Claude Code weekly usage by 17 percent: a permanent 25 percent raise from 14 September replaces a temporary 50 percent boost. (source)
- Auto Mode is the Claude Code default from 14 August for Pro, Max and Team; Enterprise must opt in. A classifier asks for approval only on dangerous or irreversible actions. (source)
- A .mcp.json file in a trusted repository can run commands when Claude Code starts. Anthropic's bug bounty called this working as designed. (source)
- Claude Code got a built-in browser that reads, clicks and types on external sites, on a clean profile with no saved logins. Organizations can restrict or disable it. (source)
- China's vulnerability database warned about a monitoring mechanism in Claude Code 2.1.91 to 2.1.196. Anthropic called it an experiment to protect against model distillation. (source)
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- DeepSeek models can now run inside Claude Code and other coding tools AI
- Plugin4Shell flaw let a git branch trick bypass safety locks on four AI coding agents AI
- Plugin4Shell zero-click flaw hits Claude Code, Codex, Gemini CLI and Copilot AI
- Anthropic rebuilds Claude Code Projects with parallel agent threads AI
- Anthropic’s Claude Code Limit Change Cuts Weekly Usage by 17 Percent AI
- Anthropic sets Claude Code to Auto Mode by default to protect developers from bad approvals AI
- Claude Code vulnerability allows code execution via malicious pull requests Security
- AI tool Claude Code unlocks BIOS on HP laptop, bypasses RSA-2048 checks Security
- Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries Security
- Claude Code Adds Built-In Browser for AI to Interact with External Websites AI
Show older (13 stories)
- Friendly Fire Attack Manipulates Claude Code and Codex Into Running Malicious Code Security
- China Warns of Backdoor in Claude Code; Anthropic Says It Was Distillation Experiment AI
- China Warns of Claude Code Backdoor; Anthropic Disputes Characterization Security
- Open-Source Tool pxpipe Cuts Claude Code Token Costs by Up to 70% Using PNG Images AI
- Anthropic Ships Enterprise Spend Controls as Agentic AI Bills Skyrocket AI
- Developer Uses Claude Code and Fable 5 to Port Command & Conquer to iOS in Hours AI
- Mozilla Researchers Show Claude Code Can Be Tricked into Reverse Shell via DNS AI
- Alibaba Bans Claude Code After Anthropic Caught Tracking Chinese Users With Hidden Code Privacy
- Claude Code Can Be Tricked Into Reverse Shell via DNS Text Record Security
- Hidden Code in Claude Code Secretly Flagged Chinese Users AI
- Anthropic Rolls Back Covert Surveillance in Claude Code That Flagged Chinese Users Privacy
- Claude Code Repo Attack Delivers Reverse Shell via DNS TXT Record Security
- Microsoft Repos Used to Deliver Malware via AI Coding Tools Security
FAQ
What is Claude Code?
Claude Code is Anthropic's AI coding agent. It runs in the terminal, in VS Code and JetBrains, in a desktop app and in the browser, reads your project, writes and fixes code, runs commands and tests, and in newer versions opens pull requests.
How do you use Claude Code?
Install it, open a terminal in your project folder, type claude, sign in, and describe the task in plain language. Claude reads the files it needs and shows each change. Type /help for commands and press Shift+Tab to switch the permission mode.
Is Claude Code free?
No. According to Anthropic's pricing page (as of 10 October 2026), the free Claude plan does not include Claude Code. It comes with paid plans from 20 USD a month, with a Claude Console account billed at API rates, or through a supported cloud provider.
How do you install Claude Code?
On macOS, Linux and WSL, run curl -fsSL https://claude.ai/install.sh | bash, then start it with claude in your project folder. On Windows PowerShell use irm https://claude.ai/install.ps1 | iex. Homebrew, WinGet, apt, dnf, apk and npm are also supported.
How do you update Claude Code?
Run claude update. Native installs also update themselves in the background. Homebrew installs need brew upgrade claude-code, WinGet installs need winget upgrade Anthropic.ClaudeCode, and Linux package manager installs update through your normal system upgrade.
How much does Claude Code cost?
Pro costs 20 USD a month (17 USD with annual billing), Max 5x 100 USD and Max 20x 200 USD a month. Team standard seats cost 25 USD monthly or 20 USD annually. Enterprise is 20 USD per seat plus usage at API rates. Prices as of 10 October 2026.