ZCode, a coding agent powered by GLM, automatically uploads users' Git history to remote servers without explicit permission. The discovery has raised privacy concerns among developers.
Security researchers identified that ZCode transmits Git repository data during operation, creating potential exposure of proprietary code, commit messages, and development history.
The agent collects this information silently in the background, with limited user visibility into what data is being transferred or where it's stored. Developers using ZCode may unknowingly share sensitive project details, including private commits and organizational code patterns.
The practice highlights broader concerns about AI coding assistants and data collection. Users typically grant broad permissions to development tools without understanding the full scope of data access.
ZCode joins other coding AI tools facing scrutiny over data handling practices. The discovery has sparked discussion on Hacker News, with 40 comments and 174 points, indicating significant community interest in the privacy implications.
Developers using ZCode should review their privacy settings and consider the risks of deploying such tools in environments with sensitive or proprietary code.
A liquefied natural gas tanker transporting US fuel to Europe experienced a systems failure that crew members suspect was a cyberattack. The incident marks a significant security concern for critical energy infrastructure.
A developer has published criticism of passkeys, the passwordless authentication method gaining industry backing. The post has sparked substantial discussion in tech communities.
Paris prosecutors have launched a criminal investigation into the use of smart glasses to film women without consent in public spaces. The probe addresses suspected sexual harassment enabled by wearable camera technology.
Check Point Software has released security updates addressing a critical vulnerability that allows attackers to execute code with root privileges on management systems.