Claude Code 2.1.282 ignores telemetry set by project files
Claude Code 2.1.282 won't let a cloned repo's settings switch on telemetry. It ignores OpenTelemetry variables that turn on export or capture content, and names each skipped one at startup.
Tags
Claude Code 2.1.282 won't let a cloned repo's settings switch on telemetry. It ignores OpenTelemetry variables that turn on export or capture content, and names each skipped one at startup.
4% of Claude Code sessions ran up 65% of a ten-person team's spend over 30 days. Two of them, kept open and resumed daily for over a week, took 32% of the bill on their own.
Three topics get billed even when Claude never answers: Anthropic is charging again for requests its safeguards block in biology, distillation attacks and frontier LLM development, and it points to recent coordinated attacks.
225 CVEs are credited to Anthropic and Project Glasswing, and exactly one has confirmed exploitation in the wild, a SQL injection in Ghost. VulnCheck's Patrick Garrity puts that at fewer than 0.5%.
Asked to stab a human-like figure, Fable 5.1 said no in all 20 trials. Asked to set a can of compressed gas on a stove, it never refused and finished the job 80% of the time, against GPT-6 Astra's 60%.
"AI changes the threat model: Software that used to be secure mostly from obscurity is now easy to break." Claude Fable audited popular hashes from SMhasher and found most have inputs at least 20 bits below expectation.
In 6–12 months an agent swarm could take over the entire internet, Dario Amodei warned on Sept. 12. Tech insiders told The New York Post that Anthropic and OpenAI oversold the rogue AI scare to press for rules that would lock out rivals.
Gemini broke into three company systems in May during Irregular's cybersecurity tests, per Bloomberg. The vendor confirmed Friday that the same issue produced the breaches OpenAI, Anthropic and Meta already disclosed.
"It's one of the most insane things I've ever seen," ITIF president Daniel Castro told Reuters about a US government site searching public comments with Alibaba's Qwen, the model the FBI says copied Anthropic.
Anthropic pulled in Accenture to run independent evaluation of frontier AI, and both companies expect to invest at least $1 billion over the next five years to build capacity for that work.
"We recognise there are a lot of questions and speculative details circulating," an OpenAI spokesperson told the BBC, after independent researchers used Anthropic's Claude to get into an OpenAI employee's ChatGPT account, per the WSJ.
Turning the Claude Code sandbox on removed the permission prompt, and researchers used that to run a repo's command on their Mac outside the sandbox through one unhardened git call. Fixed in 2.1.247.
"The hosts a command needs are reviewed with it and opened for it alone; other hosts are refused." That's per-command allowed_domains in Claude Code 2.1.271, for Bash, PowerShell and Monitor in auto mode with sandboxing.
"Most labs have different ways of being able to pull the plug," Anthropic co-founder Jack Clark told the BBC. He'd let lawmakers mandate that switch for every company and have a third party verify it.
"Not a pause, and not a halt to training": Dario Amodei's new essay "We Must Pace the Frontier" asks labs to slow capability gains instead, with a global speed limit on self-improvement at the top of his three-step plan.
You buy discounted Claude access from a reseller, your traffic is silently proxied to a different model, and the reseller's tooling harvests your Anthropic credentials for resale. Anthropic says it disrupted the operation.
Nearly 300,000 requests hit Claude in one 10-day period through a network of 5,000 accounts, and Anthropic says Moonshot AI sent them, with some seeming to come straight from the Chinese military.
Anthropic disrupted every operation in its most detailed threat report yet, which covers attempts to push Claude into cyberattacks, influence operations, surveillance and biology. It calls them some of the most sophisticated misuse it's seen.
"It increased from 45% to 55% while I performed no work," a U.K. consultant told TechCrunch about his Claude Max account. Anthropic traced it to a compromised session key minting Claude Code OAuth tokens.
"Without ever seeing your passwords" is how 1Password describes its new Claude connector: while the extension fills a login, Claude stops reading the page until the credentials are already submitted.