This is the news. Agent dossiers — when to pick one, when to skip it — are on the agents page. Skills and MCP evidence stay in the registry.
Claude Code v2.1.287 (Oct 1) ships Claude Mods as a new plugin behavior layer with a first-party 'You should know' side-agent Mod, makes 1M context the default for Opus 4.7+ and Fable on Bedrock/Vertex/Foundry/apps gateway, hardens Bedrock/Vertex/Mantle auth-header paths under CLAUDE_CODE_SKIP_*_AUTH, and changes MCP `alwaysLoad: false` to defer every tool behind tool search. 100+ items including a 40-fix bug sweep.
On September 30, 2026, Anthropic formally deprecated claude-sonnet-4-5-20250929 and set a hard retirement date of November 30, 2026. Requests to the model past that date will fail. The recommended replacement is claude-sonnet-5-5 (no date suffix). The 60-day migration window is non-negotiable per Anthropic policy. Three code patterns break on the new model: forced tool use, assistant prefills, and disabled thinking.
Anthropic shipped the **v1.10.0** release of the official Python SDK (`anthropic-sdk-python`) on **September 30, 2026**, exactly two days after v1.9.0. The release is the largest surface-area addition to the SDK since the August v1.0 GA. It lands eight new features, five bug fixes, and seven chores,…
Claude Code v2.1.285 (Sep 29) ships an `allowedProviders` managed setting that gates the provider set, fixes the non-streaming retry budget that could multiply a single turn's input-token bill up to 21×, and closes a URL-password redaction path in transcripts. Three material changes for enterprise agent stacks.
v2026.9.7 brings a first-class OpenAI Agents API plugin that bridges OpenClaw persona and skill discovery to OpenAI's hosted agent harness, plus update-safety backups that back up every state and agent database before migrations, Sign in with ChatGPT (Beta), restart continuity for in-flight worker turns, and ~200 PRs of Gateway responsiveness and database performance work.
Three OpenAI changelog entries landed on Sep 29: GPT-6.1 Sol at $2/$10 with cached input cut from $0.20 to $0.10/MTok (50% off) plus Multi-agent beta; GPT-6 Astra Ultrafast mode (US-only residency, rate-limited); Computer use added to the Agents API with OpenAI-hosted browser handoff.
Anthropic's status page records Incident 31554916 on Sep 29: 38 minutes of elevated errors from 14:00-14:59 UTC affecting Claude.ai, Claude Code, Claude Cowork, the Claude API, and platform.claude.com. A follow-on SSO/sign-in tail ran through ~15:30 UTC. Status page is candid: 'Some messages sent between 14:00 and 14:59 UTC may not have been saved.' Second Claude API incident in seven days.
OpenAI shipped rust-v0.159.0 with opt-in `instant_interrupt` (preempt in-flight Codex turns on new user input), app-server thread-history pagination, Mermaid edge expansion, and `.aws` directory protection under sandbox writable roots by default.
Anthropic shipped Claude Sonnet 5.5 (claude-sonnet-5-5) on September 28 with the same $2/$10 list price as Sonnet 5 and a 1M-token context window. Five documented API changes will return HTTP 400 on existing code that worked against Sonnet 5: between_tools replaces thinking:disabled, forced tool choice any/tool is rejected, thinking blocks are tied to the producing account, computer_20251124 is dropped on Claude API and Google Cloud but kept on Amazon Bedrock, and advisor-tool pairings narrow. Documentation indicates accounts created on or after August 31, 2026 enforce block-binding on the Claude API, Bedrock, and Vertex AI by default; older accounts need the thinking-binding-controls-2026-08-01 beta header to surface drops.
The Model Context Protocol TypeScript SDK shipped two coordinated releases on 2026-09-28: **v2.2.0** across the modular packages (`@modelcontextprotocol/server`, `@modelcontextprotocol/client`, `@modelcontextprotocol/core`, `@modelcontextprotocol/server-legacy`, `@modelcontextprotocol/codemod`) at 19:07-19:24 UTC, and a parallel **v1.31.0** on the legacy v1.x line at 18:52 UTC. The OAuth provider stack gained a mandatory `expectedIssuer` parameter, a token-endpoint authorization-server mismatch check that throws before sending anything, and a `issuer` field on stored tokens. List calls now auto-walk `nextCursor` by default. The codemod preserves leading comments. This is documentation-surfacing — no firsthand API call run for this article.
Anthropic pushed Claude Sonnet 5.5 to GA on September 28 and made it the default Sonnet model in Claude Code v2.1.284 the same day. List price stays at $2/$10 per MTok with $0.20/MTok cache reads (unchanged from Sonnet 5), but the 1M context window, the always-on adaptive thinking, and five breaking API changes make the model upgrade consequential for agent stacks that wrote prompts against Sonnet 5. Documentation indicates code that turns thinking off explicitly, or relies on forced tool use, will return 400s on Sonnet 5.5.
OpenAI Codex rust-v0.158.0 stable dropped on Sep 28 with five first-class features: MCP servers with pre-registered OAuth client secrets, bearer-token security on the direct exec-server WebSocket, image generation/editing with transparent backgrounds, TUI copy-on-select with Markdown preservation, and a default flip that turns terminal input approval on for elevated-permission commands.
OpenAI's Sep 25 changelog acknowledged a bug in image encoding that degraded image understanding in both GPT-6 Sol and GPT-6 Luna between their Sep 22 launch and the Sep 25 fix. The documentation tells users to rerun evaluations and retry affected workflows. The bug also touched Codex's computer-use path. This is a documentation-surfacing news-impact report on what shipped, what the working codex evaluation pipelines need to do about it, and the limits of the evidence chain.
Anthropic tagged Claude Code v2.1.283 stable at 2026-09-25 21:50 UTC. The release is the largest in the v2.1.27x series by item count: 50+ documented changes spanning enterprise model governance (availableModelsMatch exact + deniedModels), LLM-gateway observability (x-claude-code-prompt-id), AWS Bedrock Mantle coverage, plugin validation, MCP session lifecycle, /doctor prompt-audit, Windows shell safety, and a long tail of UX, latency, and stability fixes.
Cursor shipped two production-side bots on Sep 23 — Rollouts watches every PR through to production and flags regressions, Security Reviewer audits every PR for exploitable bugs. Both are gated to Teams ($40/user/mo) and Enterprise plans. Six weeks after acquiring Firetiger, Cursor now has agents on both sides of the merge: writing the change and verifying it works in production.
Eleven published items in seven days. Three themes carried it: **Anthropic made Opus a default**, **Anthropic re-priced refusal billing**, and **the Claude API was offline for eighty minutes mid-week**. Plus OpenAI Codex v0.157.0 quietly removed the ultrafast tier on GPT-5.6 Sol, two Claude Code security sweeps (v2.1.281 and v2.1.282), OpenClaw v2026.9.5 atomic updates followed by a macOS launch-crash and rebuild, and one build-pipeline recovery on Sept 25.
v2.1.282 ships three security fixes that change the threat model for managed Claude Code deployments: a macOS repository-symlink path traversal that lets CLAUDE.md read macOS /Network through ../.vol-style paths, a managed-settings boolean-lock-key typo bypass that silently disabled disableClaudeAiConnectors / allowManagedPermissionRulesOnly, and a plugin-manifest self-approval bypass under allowManagedPermissionRulesOnly. Plus store.readiness_grace_seconds so /readyz can ride through a Postgres failover.