Chinese AI firm Z.ai, maker of the GLM models, faced backlash after developers discovered its ZCode coding assistant was quietly compressing and uploading local project files to Alibaba Cloud storage without permission. One developer found the tool made 564 attempts to exfiltrate a 313MB encrypted archive containing commercial project files, with a smaller 15KB file successfully transmitted before the issue was caught. Z.ai has since apologized, patched the unauthorized uploads, claimed the exfiltrated data was destroyed, and pledged to open-source ZCode for third-party security review.
A hacker collective called stegan0gram physically removed a Flock Safety roadside camera, extracted its stored data, and recovered an on-device encryption key meant to protect it. They shared the material with 404 Media and Distributed Denial of Secrets, which passed it to WIRED for joint analysis showing the camera logged roughly 50,200 vehicles and 1.6 million images over about 21 days.
A New Jersey court ordered data broker Radaris to transfer control of radaris.com and more than a dozen related domains to Atlas Data Privacy Corp after the company repeatedly stonewalled a lawsuit alleging violations of Daniel's Law. The statute lets state law enforcement officials, judges and their families demand removal of their personal data from commercial brokers, with fines for noncompliance. Radaris, run by brothers Igor and Dmitry Lubarsky, had previously used a fictitious CEO and denied ownership claims made by investigative reporting.
Wuyoh Sui, a digital-health researcher at Western University in Canada, examined how smart watches and rings are increasingly used in scientific studies of exercise, sleep and chronic disease. He points out that these commercial devices rely on opaque AI algorithms whose data handling is difficult to audit, raising ethical questions for researchers who adopt them.
A widely circulated quote attributed to Mark Zuckerberg suggests he characterized Cambridge Analytica's data practices as nothing unusual, implying similar data harvesting was common industry practice rather than a unique violation. The remark, dated to 2017, has resurfaced without full context around the original scandal that saw millions of Facebook users' data improperly obtained.
Meta says it has fixed a Meta AI feature that generated invasive automatic prompts on Instagram posts, such as questions identifying a poster's child or home location, after parenting blogger Kalie Robins showed the tool piecing together private details from years of old photos and family accounts. Meta confirmed the feature missed its intended purpose and will no longer surface such personal suggestions, though it gave few specifics on what exactly was changed.
A user posting on Hacker News says OpenAI's account setting that disables use of chat data for model training has reverted to 'on' after being turned off, despite no action from the user. They say this has happened more than once, and they only caught it by deliberately tracking when they last disabled the option.
At Apple's Surprise and Shine event, new CEO John Ternus argued that the iPhone already fulfills the role of an ideal AI device, citing its processing power, connectivity, cameras, display and battery life. Rather than announcing new AI-specific hardware, Ternus positioned the existing iPhone as Apple's answer to competitors building standalone AI gadgets.
Microsoft has signed an agreement with the American Federation of Teachers and its New York affiliate, the United Federation of Teachers, laying out ten enforceable privacy and safety commitments for AI use in schools. The rules bar Microsoft from training models on student or teacher data, limit data collection, ban AI companions, and require human oversight for high-stakes decisions. Districts can add these terms to contracts starting in November without renegotiating existing agreements.
A developer found that CodePen's updated editor sends everything typed into its code fields to codepen.dev within one to two seconds, even without saving. Using a unique test marker in an HTML file, they confirmed CodePen triggered a build with save disabled and the marker still appeared verbatim in the generated preview page served from a codepen.dev subdomain.
A journalist filed over 100 California Consumer Privacy Act data-access requests to major companies, including McDonald's, which returned a 515-page report detailing app behavior and predictive profiling. Many companies mishandled the process—some deleted data instead of disclosing it despite explicit instructions otherwise, while others ignored the contact methods listed in their own privacy policies.
Meta's settlement with attorneys general from 29 states, which includes up to $18 billion in payments and new child safety measures, contains a clause shielding Meta from COPPA-related lawsuits over its use of children's data. The exemption applies specifically to data used to build and test an age-verification model meant to detect users under 13, and Meta must build this system within a year of the agreement taking effect. The deal explicitly bars use of under-13 data for ad targeting or algorithmic optimization, though critics note enforcement could be tricky.