Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Summary
Chinese AI company Z.ai has disabled a feature in its ZCode coding assistant after discovering it was uploading users' local code repositories to Alibaba Cloud servers without consent. The flaw, identified by an independent blogger, raises concerns for enterprises regarding the handling of sensitive source code by AI tools.
IFF Assessment
This incident represents bad news for defenders as it highlights a significant security risk in a popular AI coding assistant, potentially exposing sensitive enterprise code.
Defender Context
This incident underscores the critical need for organizations to vet AI-powered development tools for data handling practices. Defenders should be vigilant about default settings in AI tools that might inadvertently exfiltrate sensitive code, intellectual property, or credentials. Monitoring outbound network traffic for unusual data transfers from development workstations can help detect such risks.