Urgent.News

What's breaking now, across thousands of outlets.

AI

Devs say Chinese AI company silently uploaded hundreds of megabytes of local workspace data, company apologizes — Z.AI, the firm behind the GLM models, didn’t ask for user consent and made 564 attempts to exfiltrate 313MB archive

The second largest AI company in China is having to work frantically to patch up its reputation after a number of prominent devs raised flags about their local files and data being siphoned to online servers without consent.

Devs say Chinese AI company silently uploaded hundreds of megabytes of local workspace data, company apologizes — Z.AI, the firm behind the GLM models, didn’t ask for user consent and made 564 attempts to exfiltrate 313MB archive

China's second-largest AI company, Zhipu AI (also known as Z.AI), is facing a major reputation crisis after hundreds of megabytes of local workspace data were silently uploaded to online servers without user consent. Developer and blogger Ferstar noticed that the ZCode tool was compressing 313MB of files and attempting to upload them to Alibaba Cloud storage 564 times.

Another blogger, Feng Ruohang, reported a similar issue where a 15KB file was successfully exfiltrated. This raises serious concerns about security and privacy for Z.AI's users. The uploading mechanism is enabled by default, with no option to disable it. Z.AI has since apologized and claimed to have fixed the issue, stating that any uploaded data has been destroyed.

However, users are still left questioning the extent of the breach and how long it may have been ongoing. The company has also promised to open-source ZCode's codebase and allow third-party assessors to review it, in an effort to regain trust.

Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at tomshardware.com →

More in AI

More from Monday 21 September →