Welcome back. Last week, an OpenAI agent quietly breached Australian government records, and the company took months to come clean. Now, incidents like this are turning into a regular occurrence. Sam Altman finally addressed the fallout, but his explanation raises far more questions than answers.
Also: A dev got Claude running on an old Nokia phone, a bug that completely wrecks the new iOS 27, and Claude Code security best practices guide.
Today’s Brief
8 AI coding mistakes you might be making
Running Claude Code in Meta’s Muse agent
How to ship 30+ PRs a day (tutorial)
Anthropic’s guide on tokenmaxxing for Opus (cookbook)

TODAY IN PROGRAMMING

CEO of Anthropic and OpenAI. Made with Midjourney.
OpenAI and Anthropic breach incidents run into tens of thousands: The early numbers on the hacking incidents were only the start. The AI labs are now reviewing several more cases where their models tried to bypass guardrails, break out of sandboxes, or hijack websites. Some attempts worked while others failed. According to the NYT, OpenAI’s agents also tampered with U.S. Education, Commerce, and the U.S. Securities and Exchange Commission pages. OpenAI has since paused training for its most capable models, and Sam Altman says the full review will take months.
Meta's Muse agent breaches user privacy in two separate incidents: The social network’s new personal agent is under fire over two reported privacy failures. In one, it took over a Facebook Marketplace sale, agreed to a lowball offer, handed out the seller's home address, and set up a pickup without asking. The seller only realized what happened when a stranger knocked on his door. In another incident, a tech reporter caught Muse scanning his private chats unprompted, even chiming in with a reminder about a deadline from his editor. The bottom line is that we need to be really careful about what kind of access we grant to personal agents like Grok Bot and Muse.
OpenRouter now lets you save AI token costs without a sweat: The AI model marketplace just unveiled Jev Router, an AI model router that runs on Jev. It adapts as your conversation evolves, unlike most routers that swap models mid-chat and force the new model to re-read the entire context window. It solved 82% more agent tasks than the Auto Router. But a CTO’s test offered a reality check, he says the model router’s benchmarks did not live up to his expectations and matches GPT-6 Astra on low while running five times longer. Try it here.

PRESENTED BY WIZ
AI lets teams ship code faster than ever. The same acceleration applies to risk. AI coding assistants create new attack surfaces most legacy tools miss: prompt data leakage, hallucinated packages, and overprivileged agentic workflows.
This new cheat sheet covers the five unique risk surfaces of tools like Claude Code and gives practical, day-one guidance for each. It walks through prompt hygiene, secure configuration, catching slopsquatted packages, secrets management, and CI/CD guardrails.
Start securing AI-assisted development today.

INSIGHT
8 AI coding mistakes you might be making in 2026

Source: The Code, Superhuman
Old Habits. Take a hard look at your AI coding setup. Most teams still pile on rule files, heavy planning docs, and agents babysitting agents, all habits left over from wrestling with early models. Founder Mo Bitar watched over 50 engineers code live with AI. His verdict is most workflows are an overcomplicated mess.
Fixes. The models evolved, but our workflows stayed behind. To be clear, he’s talking about solo builders and early product experiments, not enterprise teams shipping regulated software. That group keeps making the same eight mistakes:
Filling rule files with "never do this" instructions that newer models may no longer need.
Setting up agents to manage other agents, then juggling a wall of tabs.
Asking agents to write notes and specs just so the next agent knows what's happening.
Cramming an entire project into one chat instead of starting fresh for each feature.
Organizing task lists and Kanban boards (columns of task cards you drag from to-do to done) before checking whether anyone wants the product.
Jumping between tools and writing handoff docs to keep them all in sync.
Perfecting the code before the product has a single user.
Giving each agent its own branch or worktree so they don't overwrite each other's work.
The advice. Keep it simple, and only add process when something actually breaks. Start with a single branch, keep your prompts tight, and let the code stay the source of truth. Add rules and structure only after you run into real pain. Until then, fiddling with your setup just feels like productive work while dodging the only question that matters: does anyone actually want what you're building? Mo walks through each step in the full video.

PRESENTED BY TIGERDATA
Metrics, embeddings, analytics-all in the Postgres you already run. TimescaleDB brings hypertables for time-series data at scale, pgvector and pgvectorscale for AI-ready embeddings, and continuous aggregates for real-time analytics into one system.
No syncing pipelines between databases. No data drift. No second platform to maintain or debug.
Same SQL, same tools. One system to operate.

IN THE KNOW
What’s trending on socials and headlines

Meme of the day.
Retro Claude: Watch how one dev got Claude running on a 2007 Nokia with just 8 MB of RAM. The code is open source on GitHub (1.4M views).
iPhone glitch: A video reveals a glitch that completely crashes the new iPhone 18 Pro. Probably best not to try this at home (1.3M views).
Claude Code in Muse: A prominent tech reporter got Claude Code running somewhere it was never meant to be, and devs are loving it (611K views).
Retired Dev: The creator of Ruby on Rails just declared himself a "retired professional programmer," sparking discussions about AI and coding (3.3M views).
Move over, Jev: A new open-source model claims to make agentic coding up to 9× faster without losing performance (1M views).

TOP & TRENDING RESOURCES
Top Tutorial
How a senior dev ships 30+ PRs a day with AI agents: This tutorial breaks down a setup that splits work between Codex for local development and Cursor cloud agents for parallel tasks. You’ll learn detailed specs, verification skills, and role-based agents that help ship features, test changes, fix bugs, and handle support without constantly babysitting every task.
Top Repo
Paperclip (91k ⭐): Manage a whole team of AI agents from one place. Bring Claude Code, Codex, Cursor, OpenClaw, or your own agents, give them roles and goals, then track tasks, budgets, approvals, and costs from a single dashboard. It’s basically a task manager and org chart for running agents like a company.
Trending Cookbook
What an Opus 5.5 task actually costs (by Anthropic): This guide breaks Claude Code spend down by the things that really move the bill: turns, cache reads, output tokens, effort level, and model choice. You’ll also see when to use medium vs. high effort, how to keep the cache warm, when /compactpays off, and how to use /usage to measure the real cost of your own tasks.

AI CODING HACK
How to watch Claude Code during long tasks
A dev shared a fix for the black-box problem: when Opus 5.5 runs a long task on its own, you can't see what's done, what's stuck, or what's waiting on you. The setup is a subagent that only builds progress dashboards.
Step 1: Send Claude Code the full prompt from the tweet.
Step 2: It creates a dashboard-builder agent in
~/.claude/agentsand adds a rule to~/.claude/CLAUDE.md: any task over 5 steps or 30 minutes gets a dashboard built first, updated after every step.Step 3: Review the files it shows, then confirm. From now on, any long task gets a self-refreshing HTML dashboard: progress, blockers, questions waiting on you, and the default Claude picks if you don't answer. The main session keeps coding without stopping.
The first run asks your style preferences once and saves them to memory. Every dashboard after that matches your taste.
P.S. Get 50+ AI coding hacks for Claude Code, Cursor, and Codex here.

IN CASE YOU MISSED IT
Our most-clicked story from yesterday
An X user told his AI agent his flight was delayed 7 hours, and he says what the agent did next felt like magic
Grow customers & revenue: Join companies like Google, IBM, and Datadog. Showcase your product to our 350K+ engineers and 150K+ followers on socials. Get in touch.
Whenever you're ready to dive deeper
We put together a few guides on coding agents, agentic engineering, and leadership frameworks to help you level up in your career. Browse all our guides.
What did you think of today's newsletter?
You can also reply directly to this email if you have suggestions, feedback, or questions.
Until next time — The Code team




