
16 Claude Code CVEs and Counting: Why Container Sandbox Escape Is a Vulnerability Class, Not a Bug
Sixteen CVEs against one coding agent prove container sandbox escape is a permanent vulnerability class, not a patchable bug. Here is the CVE record, the isolation ladder with real latency numbers, and why agent-generated code belongs behind its own kernel.

Anthropic Split the Agent's Brain From Its Hands: Why Infrastructure Is Now the Bottleneck
Anthropic's Managed Agents architecture splits every agent into a stateless brain, disposable sandbox hands, and a durable session log — and the hands are yours to own. A concrete mapping of who runs what, the per-second cost math of managed sandboxes versus owned machines, and the five-item checklist a real execution layer must satisfy.

Your Deploy Runbook Should Be a Skill, Not a Wiki Page
Agent Skills turn deploy, rollback, and log-triage runbooks from wiki pages agents never read into versioned skill bundles every major harness loads on demand. Here is the conversion — and why enforcement still belongs in the governed tool layer.

Run Claude Code and Codex on a Remote VPS Without Going Broke: 2026 Provider Rankings After Hetzner's Price Hike
Hetzner's June 2026 price hike killed the default self-hosted agent box. A priced VPS ranking for always-on Claude Code and Codex sessions across a 15x price spread, plus the idle-RAM breakeven math that decides when flat boxes beat metered sandboxes.

Pion Wants to Run Your Company Fully Autonomously: What Andon Labs' September 2026 Launch Assumes About the Infrastructure Underneath an Agent With a Bank Account
Andon Labs' Pion hands persistent AI agents a bank account, a terminal, and full control of real businesses. The Vending-Bench slope, the $38k cafe loss, and the infrastructure checklist — credentials, durable state, budgets, audit — a platform must build before agents get production keys.

Uber Burned Its Entire 2026 AI Coding Budget by April: What Ungoverned Agentic Spend Means for Teams Running Their Own Deploy Infra
Uber burned its entire 2026 AI budget in four months after Claude Code adoption jumped from 32% to 84% of its 5,000 engineers. The timeline, the token economics behind it, and a six-control governance playbook for teams whose agents also deploy.

A Czech Self-Hosting Hub Gave Claude Shell Access to Its Coolify Fleet: A 130-Line MCP Bridge Teardown
A Czech self-hosting hub wired Claude to its Coolify fleet through a 133-line MCP bridge — and handed the agent raw SSH instead of scoped deploy tokens. A code-level teardown of all seven tools, plus the five authorization rules a platform-owned MCP server needs.

Rent the Session or Own the Process? What Anthropic's Managed Agents Mean for Self-Hosted Agent Sandboxes
Anthropic's Managed Agents API rents you the agent session — sandbox, state, and audit trail included — while the Agent SDK leaves all of that on your machines. A side-by-side of the five platform bills, the worked cost math showing tokens dwarf the session fee, and what a self-hosted PaaS should copy.

Run a Claude Fable Security Scan with Bex Security
Run a Claude Fable security scan with Claude Code and Bex Security. The exact command, the model row that actually runs, and the sandbox policy Bex enforces around Claude.