
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Chinese artificial intelligence company Z.ai is facing a trust crisis after developers discovered that its coding assistant tool, ZCode, was silently uploading local workspace data to external servers without explicit user consent.
Summary
Even though the company, also known as Zhipu AI, apologised and patched the vulnerability, developers said the incident was likely to weaken its reputation, especially at a time when cybersecurity is becoming a central issue in the AI industry. The issue came to light...
This is a brief wire summary — the full story (linked below) has the complete details.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
We've archived 229 other articles touching the same topic (claude code, feishu, vulnerability) — see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.