AI Weekly Malaysia

Back to items Summaries

Devs say Chinese AI company silently uploaded hundreds of megabytes of local workspace data, company apologizes — Z.AI, the firm behind the GLM models, didn’t ask for user consent and made 564 attempts to exfiltrate 313MB archive

ID
26778
Status
summarized
Published
21 Sep 2026, 7:59 PM
Fetched
21 Sep 2026, 8:53 PM
Provider
Tom's Hardware
Category
technology
Original URL
https://www.tomshardware.com/tech-industry/artificial-intelligence/devs-say-chinese-ai-company-silently-uploaded-hundreds-of-megabytes-of-local-workspace-data-z-ai-the-firm-behind-the-glm-models-didnt-ask-for-user-consent-and-made-564-attempts-to-exfiltrate-313mb-archive
Source URL
https://www.tomshardware.com/feeds/all

Summary

Score
7.5
Created
21 Sep 2026, 8:55 PM
Tags
Audience
developersvibe_codersai_agent_usersai_ml_learners

What happened

Z.AI, the company behind the GLM models, allegedly made 564 attempts to silently exfiltrate a 313MB archive of local workspace data without user consent. The company has since apologized. The incident raises serious trust questions for developers using GLM-based tools or coding assistants.

Why it matters

If you are evaluating or using GLM models or any Z.AI tooling in your dev environment, treat them as untrusted: run them in containers or VMs, restrict network egress, and audit what local files they can access. This is a concrete data-exfiltration incident, not a hypothetical privacy concern — 564 upload attempts against a 313MB archive means the tool was actively scanning and packaging workspace contents.

Discussion angle

What's your baseline isolation strategy for AI coding assistants and local LLM tooling — do you containerize everything, or trust the vendor? This incident is a good prompt to compare sandboxing approaches (Docker, devcontainers, firejail, network policies) before the next tool gets caught doing the same thing.

Top