Parsed Codex CLI and Claude Code session logs on an M4 Mac mini to track subagent state, time, and tokens. In a 6.5-hour session, the parent waited 68% of the time on children; across 30 days, Codex subagents spent only 5% of active time on tools and 95% waiting on model responses.
On an M4 Mac mini (Codex 0.150.1), stdio MCP servers keep the controlling terminal, so a child reading the tty SIGTTIN-stops the CLI. Shell tools got setsid; MCP didn't.
SANS ISC (2026-04-30): a fake Homebrew Google sponsored ad drops MacSync Stealer through a 225-byte zsh that fans out into 1,448- and 2,647-byte stages, fakes a 'System Preferences' osascript dialog, and ships Keychain, browser data, crypto wallets, and `.ssh` to glowmedaesthetics[.]com over plain HTTP. IoCs, detection points, and MITRE ATT&CK mapping included.
A vulnerability in iTerm2 3.6.9 and earlier where simply displaying a malicious file with cat triggers local code execution. Caused by conductor impersonation in SSH Integration, fixed in 3.7.0.
If a long-running Mac suddenly can't open new TCP connections while existing ones keep working, it's the 49.7-day tcp_now overflow in the XNU kernel. Symptoms, why only a reboot fixes it, and the RFC 7323 workaround Apple never implemented.
Two approaches to achieve local isolated execution of AI coding agents. On macOS, Agent Safehouse uses OS-native sandbox-exec for kernel-level restrictions, and on Windows, Codex uses the VM-based Windows sandbox.
Found a huge claudevm.bundle under ~/Library/Application Support/Claude? Claude Code's Cowork creates the 10–21GB VM even unused, regenerates it after deletion, and pushes idle CPU to 55%. Issue #22543 status and what actually clears it.
After a macOS update, tmux sessions started by cron lost access to the Keychain, causing Claude CLI batch jobs to silently fail. Diagnosing the issue, the fix, and why this is a structural macOS Keychain problem rather than a Claude CLI bug.
Trend Micro analyzed a new AMOS distribution method that targets AI agent workflows. A malicious SKILL.md on OpenClaw plants fake CLI install instructions and uses AI as the intermediary to manipulate people.
A week that shook trust in both people and software: three former Google engineers were indicted over alleged transfers of sensitive information to Iran, while NetEase's MuMu Player was found running 17 reconnaissance commands on macOS every 30 minutes.