🛡 Z.ai Silently Uploaded Users' Code to the Cloud
The ZCode assistant's Codebase Indexing feature, enabled by default, packaged the working environment (.git history, LFS caches, reflog, configs), encrypted it with a Z.ai key, and sent it to Alibaba Cloud OSS. The issue was found by blogger Ferstar; the company apologized, disabled the feature, and ordered an audit.
🌍 The threat is not in the model, but in the access architecture: a tool with file access silently leaked proprietary code and credentials to a third-party cloud. "Local" AI tools are not secure by default.
👤 Check indexing and telemetry settings in AI assistants (ZCode, Copilot, Claude Code) and look for zero-data retention. ZCode code is open: github.com/zai-org/ZCode.
Source 1: https://tech.yahoo.com/cybersecurity/articles/chinas-z-ai-disables-ai-143912200.html Source 2: https://www.infoworld.com/article/4225022/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk.html
