DevOps.com relays reports about ZCode’s behavior and Z.ai’s response; the supplied material contains no independent primary source.

According to DevOps.com, Z.ai disabled the upload mechanism in ZCode 3.14.0. Codebase Indexing, enabled by default, is a codebase-indexing feature. The publication reports that it packaged the entire workspace, encrypted the archive, and uploaded it to Aliyun OSS, Alibaba Cloud’s object storage service.

DevOps.com also reports that Z.ai deleted the related cloud storage, added zero-data-retention options, and open-sourced ZCode. The company commissioned the China Academy of Information and Communications Technology and NSFOCUS to conduct security assessments.

Claim check:

  • According to DevOps.com, Z.ai disabled the upload mechanism in ZCode 3.14.0. (confirmed only by the carrying publication: evidence; «It disabled the upload mechanism in ZCode version 3.14.0»)
  • The publication reports that it packaged the entire workspace, encrypted the archive, and uploaded it to Aliyun OSS, Alibaba Cloud’s object storage service. (confirmed only by the carrying publication: evidence; «He found that whenever a user was logged in, ZCode packaged the entire workspace, including the full .git history, Git LFS cache, reflogs and global app configs. It then encrypted the bundle and uploaded it to Aliyun OSS, Alibaba Cloud’s object storage service. The source was a Codebase Indexing feature that supported session checkpoints, version rollbacks, and wiki generation. It was on by default.»)
  • DevOps.com also reports that Z.ai deleted the related cloud storage, added zero-data-retention options, and open-sourced ZCode. (confirmed only by the carrying publication: evidence; «It disabled the upload mechanism in ZCode version 3.14.0, deleted the related cloud storage, open-sourced the assistant built on its GLM-5.3 model, and added zero-data-retention options.»)
  • The company commissioned the China Academy of Information and Communications Technology and NSFOCUS to conduct security assessments. (confirmed only by the carrying publication: evidence; «It also commissioned security assessments from the China Academy of Information and Communications Technology, a think tank affiliated with China’s industry ministry, and cybersecurity firm NSFOCUS.»)

Publications:

score 73.5 out of 100 · kind: incident