The week made clear that agentic coding has crossed from novelty into infrastructure, and the security and governance bills are now coming due. Anthropic's claim that 80% of its new production code is Claude-authored, paired with Spotify and Anthropic both publishing 'AI-native org' playbooks, shows companies rewiring workflows around agents rather than typing speed. But the same week brought a cluster of attacks specifically targeting that surface: a GitHub Issue poisoning Claude Code, fake Anthropic sites pushing malware, a GitHub.dev OAuth token theft bug, and researchers demoing self-propagating AI-driven malware, all reinforcing the recurring point that permissions and containment, not model capability, are now the real bottleneck. Meanwhile the model layer kept fragmenting and commoditizing, MiniMax, Gemma 4, Microsoft's new MAI models, and OpenAI landing on AWS Bedrock, while Uber capping coding-tool spend and Anthropic's confidential S-1 filing signal that cost and capital are becoming as central to the AI story as capability. For a senior engineer, the takeaway is that the interesting problems have moved up a level: from 'which model' to how you sandbox, pay for, and audit the agents you've already given production access.
- Anthropic says 80% of its new production code is now Claude-authored, with testing time growing to fill the gap left by less manual coding.
- A wave of supply-chain and credential-theft attacks hit agentic coding tools this week: a poisoned GitHub Issue compromised Claude Code, fake Anthropic sites pushed malware, and a GitHub.dev flaw let one click steal OAuth tokens.
- Permissions and access control, not model quality, are being named the actual bottleneck for enterprise agent adoption.
- Uber capped AI coding tool spend at $1,500 per employee per month, the clearest public sign that agentic coding costs now need budget guardrails.
- Anthropic filed a confidential draft S-1 while Alphabet raised $80B for AI buildout, pulling the AI capex race directly into public capital markets.
- Researchers demonstrated self-propagating, LLM-driven malware and used AI tooling to surface a two-year-old critical Redis bug, showing offense and defense both leveling up.
Sunday, June 7, 2026
Saturday, June 6, 2026
Friday, June 5, 2026
Thursday, June 4, 2026
Wednesday, June 3, 2026
Tuesday, June 2, 2026
Monday, June 1, 2026
