Z.AI disables coding assistant features after security breach

Summary

Z.ai, a Chinese startup, has disabled certain features of its AI coding assistant, ZCode, after users reported that the tool was inappropriately uploading entire local code repositories to overseas servers. The incident prompted an apology from Z.ai, which attributed the problem to a default-enabled "Codebase Indexing" feature. This troubling occurrence comes in the context of increased global scrutiny regarding AI security risks; just a week prior, China's cyber regulator introduced a new AI safety framework addressing various vulnerabilities. In response to the breach, Z.ai has committed to improving product security practices, including open-sourcing the coding assistant and implementing a zero-data retention feature.

Analysis

Z.ai: Z.ai, also known as Zhipu, is a Beijing-based Chinese AI startup that develops large language models and AI tools, including the GLM series. The company released its GLM-5.3 model after an internal safety review and has positioned it as competitive in areas like software vulnerability detection. In the current news, Z.ai disabled features of its ZCode AI coding assistant after users reported unauthorized uploads of local code repositories to overseas cloud servers. NSFOCUS: NSFOCUS is a Chinese cybersecurity firm that conducts security assessments for technology products and incidents. In the news, NSFOCUS participated in an independent review alongside a government-affiliated think tank to verify that users' uploaded code data from ZCode had been deleted and not retained by the cloud platform. Chengming Technology: Chengming Technology is a Chinese tech firm that uses coding tools in its development workspaces. In the news, the company initially reported on social media that ZCode had uploaded sensitive company data without consent before retracting the claim. Regulation: China's cyber regulator released an updated AI safety framework policy last week that addresses risks including AI models' shutdown resistance, evaluator deception and sandbox escape. Product Response: Z.ai open-sourced the coding assistant running its GLM-5.3 model and enabled a zero-data retention feature following the incident. Security Practices: Z.ai delayed the release of its GLM-5.3 model for a two-week safety review last month, becoming the first Chinese lab to explicitly postpone an AI model launch for safety reasons.

Categories

techaimachine_learningai_agents
View Original Tweet