NewsClaude Desktop Extensions CVSS 10 RCE Anthropic Declines FixLayerX Security·high signalXBlueskyLinkedInCopy linkCVSS 10 zero-click RCE in DXT. Google Calendar event achieves full system compromise. Anthropic declined to fix.SourceSource pageLayerX Security↳ Follow the threadPolicy dependency / Stack layer'Do this as quickly as possible' repeatedly got a Claude session flagged by a corporate security directorr/ClaudeAIPolicy dependency / Stack layerCROSS-CATEGORY: On the Same Day, Anthropic Moved Into Documents and Decks While OpenAI Moved Into Ad Sales, CRM and EcommerceThe Next Web and Search Engine Land (two independent same-day writeups of two separate primary announcements)Policy dependency / Stack layerAnthropic Folds Cowork Into Claude and Ships Docs, Slides and Design as Editable SurfacesAnthropic (corroborated by TechCrunch, The Next Web and Dataconomy, all 2026-09-16/17)Stack layer / Threat patternA Show HN tracker puts numbers on model staleness: Gemini 3.1 Pro shipped 13 months after its training cutoffShow HNPolicy dependency / Stack layerOverlapping VS Code extension writes were leaving ~/.claude/settings.json unparseableGitHubPolicy dependency / Stack layerTip: Claude Code's Bash tool was re-sourcing your shell profile after every plugin reloadClaude Code ChangelogStack layer / Threat patternClaude Code 2.1.273 Stops Loading a Repo-Chosen Memory Directory Into the Prompt Under Read BlockingAnthropic (claude-code releases)Stack layer / Threat patternClaude Code 2.1.274 adds a bounded MCP startup wait, a managed-settings OTel event, and stops corrupted transcripts from retrying a 400 foreverClaude Code changelog