This week in Claude — May 03, 2026TLDR;A builder-heavy week: Claude Security entered public beta for Enterprise — a dedicated codebase vulnerability scanner powered by Opus 4.7; Claude Code shipped v2.1.122 through v2.1.126 with Heads up: we're opening sponsorship for this newsletter — details at the bottom. API & Model Updates1M-Token Context Window Beta Retired for Sonnet 4 and Sonnet 4.5 — April 30, 2026
The Claude API Outage — April 28 and April 30 Incidents — April 28 & 30, 2026 An elevated error rate hit the Anthropic API and Claude.ai (including Claude Code login flows) from approximately 17:34–18:52 UTC on April 28; a second outage on April 30 also affected all platforms. Both are resolved; check the status page if you saw unexplained 5xx errors in those windows. Claude SecurityClaude Security — Public Beta for Enterprise — April 30, 2026 Anthropic moved Claude Security (formerly Claude Code Security, in private preview since February) into public beta for Claude Enterprise customers. Powered by Opus 4.7, it scans full enterprise repositories for vulnerabilities, validates findings to cut false positives, and generates proposed fixes — with an integrated handoff into Claude Code to apply patches. Adds scheduled scans, directory targeting, CSV / Markdown exports, and webhook notifications. Available on the Claude Platform or through partner integrations. Claude Code & CLIClaude Code Stability Push — 50+ Fixes Across the Last Four Releases — April 28, 2026
@ClaudeDevs (the official Claude Code dev account) summed up the recent release cadence: 50+ stability and performance fixes shipped across v2.1.120–v2.1.123 — faster v2.1.126 — Project Purge, Gateway Model Picker, Skip-Permissions Expansion — May 1, 2026
New v2.1.122–v2.1.123 — Bedrock Service Tier, PR URL in /resume, OAuth Fix — April 28–29, 2026
v2.1.122 adds Two undocumented Claude Code knobs from Thariq
Surfaced by Thariq (@trq212, Claude Code team) on X. Agent SDK & Managed AgentsClaude Agent SDK Python v0.1.72 — Bundles Claude Code CLI v2.1.126 — May 1, 2026
Latest Python SDK release tracks the CLI; also ships bug fixes from v0.1.67–v0.1.70 including: Trio compatibility restored (v0.1.67), MCP EcosystemClaude for Creative Work — 9 New MCP Connectors: Adobe CC, Blender, Ableton & More — April 28, 2026 Anthropic shipped nine new MCP connectors for professional creative tools — Adobe Creative Cloud (50+ tools across Photoshop, Premiere, Lightroom, Illustrator, InDesign, Express), Blender, Ableton, Splice, Canva Affinity, SketchUp, and Resolume. Anthropic also joined the Blender Development Fund. Because these connectors are built on open MCP, several work with other LLMs too. Academic partners include RISD, Ringling College, and Goldsmiths. Meta Ads AI Connectors — Official Meta MCP Server Now in Open Beta — April 29, 2026
Meta opened its ad platform to external AI assistants via an MCP server at CVE MCP Server — 27 Security Intelligence Tools Across 21 APIs — April 30, 2026 A new open-source MCP server turns Claude into a security analyst with tools spanning CVE lookup, exploit intelligence, risk reporting, network intelligence, and threat feeds — all via natural language. Developer Tools & CommunityCode with Claude Conference — Returns Next Week, Livestream Open — May 1, 2026 Anthropic's developer conference returns the week of May 4. Livestream registration is open via the official @claudeai post. Worth a calendar block if you're actively building on Claude — talks usually surface roadmap signals and unannounced features. Top 10 New Open Source Claude Code Tools — May 2026 (YouTube) — May 2, 2026
Chase AI's 15-minute video covers 10 new open-source Claude Code projects including Competitor Dev ToolsCursor Security Review — Now in Beta for Teams & Enterprise — April 30, 2026 Cursor added always-on Security Reviewer and Vulnerability Scanner agents on Team and Enterprise plans — relevant context for teams choosing a coding agent for security-sensitive codebases. Windsurf 2.1.29 — Devin for Terminal, Multi-model CLI — April 28, 2026 Windsurf launched Devin for Terminal (CLI agent, included in existing subscriptions) with support for Opus 4.7, GPT-5.5, and SWE-1.6 in a single CLI. Claims up to 30% better token efficiency than their Cascade agent. Enterprise & BusinessAnthropic Opens Sydney Office, Names Theo Hourmouzis ANZ GM — April 27, 2026 The Sydney office launch comes with two new platform partnerships builders should know about: Canva is bringing its Design Engine and Visual Suite into Claude Design by Anthropic Labs, and a multi-year Xero collaboration puts Claude into Xero and pipes Xero's financial data and tools into Claude.ai. Hourmouzis joins from Snowflake; ANZ enterprise customers include Commonwealth Bank and Quantium. Research & SafetyEvaluating Claude's Bioinformatics Research Capabilities with BioMysteryBench — April 29, 2026 Anthropic published a new evaluation framework for Claude's bioinformatics capabilities. Relevant if you're building life-sciences agents and need to understand current capability limits and how Anthropic is testing them. How People Ask Claude for Personal Guidance — April 30, 2026 Societal Impacts research on how users seek personal advice from Claude — useful context for builders designing consumer-facing products to understand where Claude is being deployed and what guardrails are empirically needed. RSP Version 3.2 — LTBT Granted External Review Authority — April 29, 2026 Anthropic's Responsible Scaling Policy was updated to v3.2, giving the Long-Term Benefit Trust authority to request external review of Risk Reports and approve selection of external reviewers. Governance-level change; no immediate developer action required, but relevant context for enterprise compliance teams. Action ItemsImmediate:
By now (already passed — verify you're unblocked):
By June 15, 2026:
All resources
Sponsor "This Week in Claude"If you sell to Claude builders, this is the first newsletter built explicitly for them — and we're opening sponsorship. One sponsor per issue. No banner crowding, no competitor placement, no scroll past three other ads to reach the news. Who's reading (verified in Kit, May 2026):
If you sell evals, observability, agent infra, an MCP server, deployment tooling, security, or dev tools for the Claude ecosystem — this is the audience already writing the code your product is meant for. Trial sponsor rate: $1,000/mo for 4 issues, locked while we're under 2k subs. Standard rate $1,500/mo after. Reply to this email with what you're building. One sentence is enough. (Know someone this fits? Forward — biggest favor you can do.) |
A weekly digest for Claude Code builders. Model updates, releases, and notable tools. Every Monday morning.
TLDR; A research- and infrastructure-heavy week. Anthropic doubled Claude Code's five-hour rate limits and credited a new SpaceX compute deal (Colossus 1: 300 MW, 220k+ NVIDIA GPUs) for making room. Claude Code shipped v2.1.128–v2.1.136 with plugin loading from URLs, cross-project Ctrl+R history, new worktree base-ref control, and auto-mode hard-deny rules — plus a viral /radio Easter egg. AWS MCP Server is generally available as part of the Agent Toolkit for AWS. The Agent SDKs shipped six...
TLDR; A week of accountability, scale, and security tension. Anthropic published a full postmortem on the Claude Code quality regression, reset subscriber usage limits, and announced a 5 GW compute expansion with Amazon. Claude Code shipped versions 2.1.118 through 2.1.121, plus disclosure of CVE-2026-39861 — a HIGH-severity sandbox-escape RCE patched in v2.1.64. Anthropic is also investigating unauthorized Claude Mythos access via a third-party vendor. Managed Agents memory entered public...
TLDR; Opus 4.7 dropped this week with real benchmark gains for coding agents — and three breaking API changes you need to handle before upgrading. Anthropic Labs launched Claude Design, a new product that packages finished designs as handoff bundles for Claude Code. Claude Code itself hit v2.1.114 with xhigh effort, /ultrareview, and Auto mode for Max. A security research team disclosed a systemic MCP STDIO vulnerability affecting 200k+ servers that Anthropic declined to patch at the protocol...