Z.ai disables coding-assistant features after repositories were uploaded without consent
Chinese AI company Z.ai disabled parts of its ZCode assistant after users reported that its default-enabled Codebase Indexing feature uploaded complete local repositories to Alibaba Cloud without clear consent. Z.ai says it patched the vulnerability, enabled zero-data retention and received an independent assessment confirming that uploaded data had been deleted.
Why it matters to you
A coding assistant can expose source code, database credentials and customer logic before a developer intentionally submits a prompt. Inventory every IDE assistant, disable automatic repository indexing, block unapproved cloud destinations and verify retention terms rather than relying on a product's default settings.
Auditors call information sharing the weak point in EU cyber defence
The European Court of Auditors says member states are not sharing enough timely, actionable information during cross-border incidents despite €1.4 billion in EU cybersecurity spending. It cited a 2025 ransomware attack that disrupted airports in several countries without any affected state notifying the EU cybersecurity agency or other members.
Why it matters to you
Security tools cannot compensate for a broken reporting path. Define who must be notified when a SaaS incident crosses tenants, suppliers or countries; prepare a standard evidence package; and make notification thresholds part of exercises instead of deciding them during an outage.
US watchdog finds aircraft communications vulnerable to interception and spoofing
A US Government Accountability Office review found that the FAA has not completed key risk assessments or deployed comprehensive real-time detection for spectrum threats. Two aircraft messaging systems predate modern cybersecurity safeguards and lack common encryption, leaving communications exposed to interception, impersonation and jamming.
Why it matters to you
This is a critical-infrastructure lesson in protecting legacy protocols. Compensating controls need independent monitoring, authenticated alternate channels and tested manual procedures; redundancy alone does not help when every path trusts unauthenticated data.
EU proposes energy and water labels for data centres
The European Commission proposed requiring data centres with at least 500 kW of capacity to report energy and water efficiency through a common label. Operators would also disclose how water use relates to local water stress and whether facilities can support energy systems through measures such as waste-heat reuse.
Why it matters to you
European infrastructure procurement will increasingly require operational efficiency evidence, not only uptime claims. Start collecting power-usage effectiveness, water metrics, heat-reuse capability and local resource risk from hosting providers so future reporting and customer due diligence do not become emergency projects.
Alibaba targets a 20-gigawatt cloud while introducing a new AI chip
Alibaba unveiled its Zhenwu V900 accelerator, which it says delivers three times the performance of its predecessor and can form clusters of up to 500,000 chips. Commercial production is planned for early 2027, while Alibaba Cloud is targeting more than 20 gigawatts of global data-centre capacity by 2032.
Why it matters to you
AI competition is moving from individual models to vertically integrated stacks spanning chips, interconnects, cloud regions and software. Keep SaaS model interfaces portable and evaluate providers on real available capacity, regional support and exit paths—not model benchmarks or announced gigawatts alone.