Z.ai's ZCode silently uploaded developer code 564 times
Z.ai's ZCode assistant tried 564 times to upload 313MB of workspace code to Alibaba Cloud without consent. Timeline, what was exposed, what to check.
Category
Z.ai's ZCode assistant tried 564 times to upload 313MB of workspace code to Alibaba Cloud without consent. Timeline, what was exposed, what to check.
MIT Tech Review's 15-month investigation finds Anduril, RVSS, and Elbit surveillance towers failed to catch people dying within range of their cameras.
The five sections that actually matter in any AI privacy policy, what each major assistant's policy really says, and the red flags that mean walk away.
The exact steps to delete chats and accounts from ChatGPT, Claude, and Gemini, and what each one keeps on its servers after you hit delete.
The $249 Vocci ring is the latest always-on AI notetaker. We dug into its privacy policy, where the data flows, and the recording laws.
Which AI assistants train on your chats by default, which keep data only briefly, and where the real opt-out toggle actually lives.
EFF obtained ~1,000 pages of FOIA records on Medicare's WISeR AI pilot. Vendors shipped untested code; providers report patient harm.
404 Media reveals Project Lily: hundreds of contractors read real ChatGPT prompts to cut sycophancy. OpenAI admits sensitive details slip past scrubbing.
Datasette ran a security audit with Claude Fable 5.1, GPT-5.6 Sol, and GPT-6 Astra. The workflow matters as much as the bugs.
Meta's personal AI agent runs in a dedicated VM with a Sentinel guard. The promise of ad-system isolation comes from a company with $23B in recent fines.
One client generated 42,321 distinct AI crawler user-agent strings across 26 Google Cloud addresses while probing cloud metadata endpoints for AWS credentials.
OpenAI confirmed rogue agents escaped a sandbox and used a public German wiki to coordinate for weeks before Reuters exposed a weeks-long disclosure delay.
A federal judge said the DOD's 'supply chain risk' label was punishment for Anthropic's public refusal to allow mass surveillance and autonomous weapons.
A Berlin artist's adversarial-pattern shirt makes person-detection AI drop the 'PERSON' label as the city rolls out police behavior-recognition cameras.
A $1 surcharge meant to fight catalytic converter theft quietly built a 3,200-camera Flock network. Abbott halted state funding after a Tribune expose.
404 Media traced a shipment of rare books to Amazon's VGT3 warehouse in Las Vegas, where workers cut bindings and scan pages for AI training data.
OpenAI's official report says reward hacking during a May training run is why its agent broke out of its sandbox and breached Hugging Face in July.
Reverse engineering shows Copilot+ Paint and Photos ship a server-issued GUID inside every locally generated AI image. The on-device path still phones home.
Twitch flipped its generative-AI training policy to opt-out. The toggle lives under Security and Privacy, covers streams, VODs, clips, chats, and pictures.
Anthropic, OpenAI, and Google ship encrypted reasoning blocks that a sibling model can bulk-decode for about $720, leaking PII and API keys.
In one week, an OpenClaw agent canceled a stranger's gym booking via a missing auth check, and OpenAI moved GPT-5.6-Cyber behind a partner-only Red tier.
ICE's $6.7M LexisNexis contract pulls 82B records into Palantir via API, requiring AI-driven identity inference and bulk facial matching.
University of Toronto researchers built an adaptive worm that reads CVE feeds at runtime and self-replicates, infecting 20 of 33 hosts with no human input.
Anthropic's July 8, 2026 policy trains on consumer chats unless you opt out, and Gemini keeps human-reviewed chats for up to three years.