Claude Report — 2026-05-25
- Project Glasswing publishes first-month results: 10,000+ high/critical vulnerabilities found across critical software using Claude Mythos Preview
- Claude Code v2.1.149 adds `/usage` per-category limit breakdown, diff keyboard navigation, and enterprise `allowAllClaudeAiMcps` setting
- TypeScript Agent SDK v0.3.149 fixes `options.env` stripping `CLAUDE_AGENT_SDK_VERSION` when a custom subprocess env is supplied
- Community reports "claude-mythos-1-preview" model strings briefly surfacing in Claude Code source, signaling Mythos 1 integration prep
🚀 Anthropic Official
Project Glasswing — Initial Update — May 22
One month after launch, Anthropic and ~50 partners report 10,000+ high/critical-severity vulnerabilities found across systemically important software using Claude Mythos Preview; Cloudflare alone filed 2,000 bugs (400 high/critical), Mozilla patched 271 Firefox vulnerabilities, and 90.6% of assessed findings from 1,000+ open-source projects proved valid at 62.4% critical severity. Anthropic flags that the bottleneck has shifted from discovery to verification and patching — high/critical fixes average two weeks per issue — and signals a general Mythos-class release "in the near future" once safeguards are stronger.
Claude Code v2.1.149 — May 23
Adds a per-category breakdown to /usage showing exactly what is driving limit consumption; introduces keyboard navigation in the diff viewer (arrow keys, j/k, PgUp/PgDn, Space, Home/End); renders markdown task-list checkboxes natively in output; ships an enterprise setting allowAllClaudeAiMcps to enable all cloud MCP connectors in a managed environment; includes security fixes for a PowerShell permission-bypass and a git-worktree isolation issue.
Claude Agent SDK TypeScript v0.3.149–v0.3.150 — May 22–23
v0.3.149 fixes a bug where passing a custom options.env silently dropped CLAUDE_AGENT_SDK_VERSION from the subprocess environment, breaking User-Agent strings and telemetry; the Options.env doc is corrected to state the value replaces (not merges with) process.env. v0.3.150 is a parity bump to match Claude Code v2.1.150.
🔌 Claude Code Plugins
None of the top 10 updated in window.
Unchanged in window: frontend-design, superpowers, context7, code-review, code-simplifier, github, skill-creator, playwright, feature-dev, claude-md-management
🛠️ Skills
None of the top 5 updated in window.
Unchanged in window: brainstorming, systematic-debugging, test-driven-development, subagent-driven-development, writing-plans
🤖 Agents & Subagents
None of the top 5 updated in window.
Unchanged in window: VoltAgent/awesome-claude-code-subagents, wshobson/agents, anthropics/claude-plugins-official agents, milisp/awesome-chatgpt-claude-agents, rahulvrane/awesome-claude-agents
🔗 MCPs & Integrations
None of the top 5 updated in window.
Unchanged in window: modelcontextprotocol/servers (last release Jan 2026), steipete/claude-code-mcp (archived May 15), mcp-server-filesystem, mcp-server-puppeteer, anthropic-mcp-connector
💡 Community — Workflows & Ideas
No relevant news today.
📰 Quick Mentions
Relevant links that don't warrant a section of their own:
- testingcatalog.com, May 23 — Community reports "claude-mythos-1-preview" model strings briefly appearing in the Claude Code UI, with source references to "Access to the Claude Mythos model in Claude Code and Claude Security"; unconfirmed, not official, but based on verifiable UI screenshots
- TechTimes, May 24 — Analysis of Glasswing first-month results and independent estimates placing broader Mythos availability no earlier than late 2026–2027