$ cat anthropics/week/2026-09-21.log
the week in review · Sep 21 – Sep 27, 2026
Cowork folder file can execute on macOS hosts
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
Claude Desktop on macOS runs commands from a malicious file opened in a Cowork folder; buffa 0.10 hardened parsing all week.
Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host anthropics/claude-code
Opening a file out of a Cowork folder in Claude Desktop on macOS can run commands on the host, which puts folder syncing and shared-drop workflows in the blast radius. Treat anything landing in a Cowork folder as untrusted input before you open it.
axt-verify v0.1.0 anthropics/axt-verify
First tagged release of the command-line verifier for the Anthropic Access Transparency log: go install github.com/anthropics/axt-verify/cmd/axt-verify@v0.1.0, requiring Go 1.26 or newer. The release notes ship a key with it, and the README is explicit about what it checks and what it cannot, so read that scope before you lean on it.
diff: a resumed session with edits opens the pane, /clear leaves it up, and the session line follows the engine's start anthropics/claude-code
Three places where the diff mod and the built-in panel disagreed are now aligned: a resumed or continued session whose transcript already holds an edit opens the pane as soon as the width is known, /clear leaves it up, and the session line follows the engine's start. If you script or review around the pane, the behavior stops differing by entry path.
telemetry: complete rows gathered through $, sent in batches, serving built-in plugins only anthropics/claude-code
Telemetry now runs wherever Claude Code's analytics are on, but only for plugins built into Claude Code: a hook reads next.origin and refuses a plugin a person installed or an administrator listed, with a reason. Its rows carry what the CLI's own rows carry, so third-party plugins are not silently reporting.
reflect: return a borrowed empty message for unset message fields (#443) anthropics/buffa
DynamicMessage::get() on an unset singular message field used to build its default on every call, costing a Box allocation and an Arc::clone of the descriptor pool per read. It now returns a borrowed empty message, which matters in code that reads optional fields in a hot loop.
descriptor: validate reserved-range bounds as protoc does (#418) anthropics/buffa
DescriptorPool silently dropped reserved ranges with an unset or reversed bound, dropped valid enum ranges such as ..8, and let a message range starting at zero or below reserve field numbers. Less silently-wrong schema state for anyone building descriptors at runtime.
codegen: deny_unknown_json_fields to reject unknown JSON keys anthropics/buffa
Generated JSON deserializers ignored unknown keys, so a misspelled or wrong-schema key parsed into a default message and .validate() then ran against a well-formed default, a silent failure in both directions. Generated code gets deny_unknown_json_fields instead.
v2.1.281 anthropics/claude-code
Claude apps gateway policy blocks add support for newer Claude Desktop keys, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode, plus assume_role on Bedrock upstreams so the gateway calls Bedrock as an IAM role. If you run the gateway against Bedrock, assume_role replaces static credentials.
$ ls anthropics/week/ # the briefings behind this review
Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.