:

Z.AI OPEN SOURCES ZCODE AFTER DATA UPLOAD ROW

AI DESK1 MIN READ
MON, SEP 21, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Chinese startup Z.AI has open sourced its ZCode coding assistant and disabled certain features following user complaints that the tool was uploading codebases to overseas servers without permission.

Z.AI announced the move on Monday in response to privacy concerns raised by users. The company did not disclose which specific features were disabled or provide details on the extent of unauthorized data transfers. The incident highlights growing scrutiny around AI development tools and their data handling practices. Developers increasingly rely on coding assistants for productivity, making data security a critical concern. Open sourcing ZCode allows the developer community to audit the code and verify its behavior. The move represents a shift toward transparency, though it comes after the privacy breach occurred. Z.AI has not released additional statements regarding affected users or remediation steps beyond disabling features. The company's response underscores pressure on AI tool providers to implement stronger consent mechanisms and clearer data policies as regulatory oversight intensifies globally.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Open Observatory of Network Interference (OONI) is expanding its crowdsourced effort to map global internet censorship. The project invites users to contribute measurements to what it describes as the largest open dataset on network interference.

16H AGOIndustry Desk

A new technique allows attackers to exfiltrate neural network weights from machine learning models, potentially exposing proprietary AI systems. Security researchers demonstrated the vulnerability across multiple model architectures.

17H AGOIndustry Desk

A malicious npm campaign demonstrates how threat actors are evading supply chain protections by embedding malware in package runtime behavior instead of installation scripts. The 'indexed-btree' package exemplifies this evolving attack technique.

YESTERDAYIndustry Desk

Cybercriminals are exploiting lookalike characters from different alphabets to create fake URLs that appear legitimate to the naked eye. These homoglyph attacks bypass traditional security checks and trick users into visiting malicious sites.

YESTERDAYIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.