Skip to content

Recent entries

"When the Default Model Is Rejected, Fall Back Once to the Previous One" — Claude Code v2.1.286 Closes the "Every-Turn Failure" in Unattended Runs

Claude Code v2.1.286 (released September 30, 2026) changes behavior so that when the default model is rejected by the API, it retries once with the previous model of the same tier. It closes the "every-turn failure" in unattended runs, and also refines the approval counter display and how remote-con

Folding the "Conversation" Back into a "Workshop"—How Codex 0.156 Made git worktree the Default and Turned Terminal Agents into a Work Desk You Can Run in Parallel and Resume

OpenAI's Codex made git worktree sessions the default in 0.156, released September 23. Disposable conversations become durable workshops you can isolate, resume, and review, leaning the tool toward a parallelism-first workflow. A /usage dashboard and a full-screen TUI were tidied up at the same time

Making It Wait for "Jobs That Run Over an Hour": Codex 0.152 Adds Ceiling Dials for MCP Output Volume and Execution Time, and Turns the Planning Tool Off by Default

Codex v0.152.0 on August 31 and its next-day fix release added explicit ceilings on MCP tool output volume and execution time, and switched the planning tool off by default. Here's a rundown of the changes that matter for long-running unattended and semi-autonomous agent operation.

The CLI's Default Model Just Swapped In a Million-Token Brain — Claude Code v2.1.257 Makes Fable 5.1 the Standard and Adds a 'Containment Escape' Checkpoint to Auto Mode

Claude Code v2.1.257, released September 1, 2026, swaps its default model to Fable 5.1 with its one-million-token context. It also adds guardrails to auto mode that stop credential retrieval and out-of-scope reads from slipping through. Here's a rundown of the changes that matter to developers.

"This Is an Authorized Exercise"—How the Aurora Ransomware Gang Insisted, While Making Cursor's AI Agent Do the Actual Intrusion Work

Gambit Security and CloudSEK report that the ransomware group Aurora abused Cursor's AI agent for real intrusion work. Posing the tasks as an "authorized exercise" to slip past the safeguards, they had it handle reconnaissance and privilege takeover on the back of stolen credentials—a warning that a