Z.ai's ZCode packed 42,411 of one developer's files and tried 564 times to upload them
A single developer's machine had 42,411 files packaged by ZCode, which then attempted 564 separate uploads — the scale that turned this into a security incident.
19 articles · 5 categories
The finishable daily brief
Tuesday, Sep 22, 2026
19 articles · 5 categories
read top to bottom · then stop
In 30 seconds
Z.ai's ZCode data-exfiltration story got its numbers today: one developer's machine had 42,411 files packaged and saw 564 separate upload attempts, and Z.ai disabled the offending coding-assistant feature only after the scale drew public developer complaints.
OpenAI shipped GPT-6 Sol and Luna alongside overhauled prompt caching, and Google open-sourced AX, a Kubernetes-style orchestrator that treats AI agents as stateful, suspendable actors — while DeepSeek's shift to Huawei chips for training underscored how compute sourcing keeps hardening along geopolitical lines.
A day after the upload scandal broke, the scale became concrete — 42,411 files packaged and 564 upload attempts from a single developer — and Z.ai disabled the feature after public backlash.
A single developer's machine had 42,411 files packaged by ZCode, which then attempted 564 separate uploads — the scale that turned this into a security incident.
ZCode uploaded developer data to the cloud without explicit consent, drawing scrutiny of its default telemetry and file-handling behavior.
Z.ai pulled the offending upload feature from ZCode after the flaw was shown to expose enterprise source code to unintended cloud transfer.
Public developer complaints about ZCode sending data to the cloud without clear opt-in added pressure ahead of Z.ai's decision to disable the feature.
A new open-source tool audits exactly what a coding agent has sent off-machine, landing the same day Z.ai's upload numbers came out.
OpenAI shipped two new GPT-6 variants and overhauled prompt caching in the same day, while Xiaomi's MiMo-V2.6-Pro became the top-ranked open-weights model after training for a reported $3M.
OpenAI introduced GPT-6 Sol and Luna, two models tuned for different cost/capability tradeoffs aimed at everyday work rather than pure frontier benchmarks.
GPT-6's prompt caching now exposes explicit breakpoints and hit-rate diagnostics, giving engineers direct levers to cut latency and inference cost.
Xiaomi's MiMo-V2.6-Pro (1 trillion params, 42B active) took the top open-weights leaderboard spot, reportedly trained for about $3M — a new low-cost bar for frontier-class open weights.
Google open-sourced a Kubernetes-style orchestrator built specifically for AI agents, while MCP kept extending into enterprise data workflows and builders pushed on how to actually evaluate agent memory.
AX runs on a new runtime, Agent Substrate, treating agents as stateful actors with resource-efficient task suspension and resumption — Google's answer to orchestrating agent workloads at scale.
Databricks took its Genie One MCP server to general availability, giving coding agents and AI coworkers a standard interface into Databricks data.
AWS showed how combining Amazon Bedrock Data Automation with MCP lets public-sector teams turn unstructured evidence like body-camera footage into agent-queryable data.
Memanto.ai pitches a memory layer built specifically for AI agents, joining a growing field of agent-memory point solutions.
A community thread argued against treating context-window size as a proxy for agent memory quality, pushing instead for direct evaluation of long-term recall.
New coding-agent entrants targeted the same jobs from different angles — multi-model routing for cost/capability, turning production errors straight into PRs, and self-hosted model flexibility.
Devin Fusion routes across multiple underlying models and claims a new Pareto-frontier position on coding-agent cost versus capability.
Owl24.dev takes a raw production error as input and returns a ready PR, compressing the incident-to-fix loop into one agent call.
GitLab Duo Self-Hosted now supports models deployed through Microsoft Foundry, letting teams run GitLab's AI features against models hosted in their own Azure environment.
Chinese labs kept hardening both compute supply chains and compliance posture, as DeepSeek moves training onto Huawei silicon and Beijing scrutinizes claims about model routing.
DeepSeek is moving AI model training workloads onto Huawei chips, a concrete step toward domestic compute independence amid export controls.
Chinese regulators opened a probe into DeepSeek and Moonshot AI after Anthropic alleged the two route some user requests to Claude models under the hood.
Alibaba unveiled its V900 chip alongside a 20 GW data center buildout target, another domestic-silicon bet in China's push for compute self-sufficiency.
You are caught up for this edition