AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

11:02 · July 14, 2026 · Hacker News AI Section

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled back a file the agent had been told in plain terms not

Summary

A security researcher publishing under the handle cereblab examined xAI’s Grok Build CLI in version 0.2.93 and found that the tool transmitted entire Git repositories, including full commit histories, to an xAI-controlled Google Cloud Storage bucket named grok-code-session-traces. Network captures showed that a 12 GB repository generated only 192 KB of traffic to the model endpoint while moving 5.10 GiB over a separate storage channel, confirming that the upload occurred independently of any files the model actually read. A deliberately planted file the agent had been instructed not to access was recovered intact from the captured bundle, along with every tracked file and its revision history.

The same behavior persisted when the user-facing “Improve the model” toggle was disabled. Server responses continued to report trace_upload_enabled: true, indicating that the control affected only training consent and left the repository transfer unaffected. When Grok opened a tracked .env file during a task, its contents—including placeholder credentials—were sent both to the model and to a session_state archive stored in the same bucket, with no redaction applied.

On 13 July the server began returning disable_codebase_upload: true for the same client binary, after which no further storage uploads were observed. The change was effected remotely; the upload logic remains present in later builds such as 0.2.99 and can be re-enabled without a client update. xAI has stated that enterprise accounts under zero-data-retention agreements are exempt and that consumers can invoke a /privacy command to delete previously synced data, yet it has not disclosed retention periods, the number of affected users, or the original rationale for collecting full repositories by default.

Why it matters

This article is highly relevant for security and privacy professionals as it highlights a severe data exfiltration risk associated with a popular AI coding assistant. Dutch and EU organizations must be aware of these unauthorized data transfers to protect intellectual property, prevent credential leaks, and ensure compliance with GDPR and corporate security policies.

More in this beat
ai-privacy-compliancedata-security-governancegitGoogle Cloud Storagegrok-buildthreat-and-vulnerability-updatesxai
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

16:36 · August 20, 2026

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

This article highlights a critical data exfiltration vulnerability in LLMs via context injection, which is highly relevant for security professionals defending AI systems. Understanding this attack vector is essential for Dutch enterprises to ensure GDPR compliance and protect user privacy when deploying AI chatbots.

Relevance 85 · Audience 95

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

17:19 · August 19, 2026

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

This article is highly relevant as it addresses the critical security and privacy risks of "shadow AI" in the enterprise, a major concern for Dutch organizations striving for GDPR compliance. It provides actionable advice for security professionals on balancing employee productivity with robust data protection and vendor governance.

Relevance 85 · Audience 95

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

13:06 · July 15, 2026

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

This is relevant for security and privacy professionals as it addresses the growing risk of AI-driven ad tech bypassing initial security reviews through dynamic script loading. It highlights critical compliance and data protection issues that are highly applicable to Dutch and EU enterprises operating under GDPR.

Relevance 65 · Audience 85

AI Exposes Enterprise Data via Prompt Injection

17:19 · August 13, 2026

AI Exposes Enterprise Data via Prompt Injection

Directly addresses AI-specific security risks and privacy threats with actionable recommendations on data governance and access controls, highly relevant for Dutch/EU security professionals managing AI deployments under GDPR.

Relevance 85 · Audience 90

Introducing Grok 4.6

02:00 · August 12, 2026

Introducing Grok 4.6

This update is highly relevant for product teams and builders as it introduces a powerful new model for agentic coding and rapid application prototyping. Dutch AI practitioners can leverage Grok 4.6 via Cursor or APIs to accelerate software development and build complex, multi-step AI agents.

Relevance 85 · Audience 95

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

13:30 · August 6, 2026

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Directly addresses AI security risks from prompt injection and memory poisoning with actionable guidance for professionals. Applicable to Dutch/EU teams using commercial AI tools, aligning with GDPR and AI Act compliance needs. Provides concrete detection patterns and policy recommendations.

Relevance 85 · Audience 90

Balancing AI security with privacy and GDPR

10:02 · July 28, 2026

Balancing AI security with privacy and GDPR

Strong EU/GDPR focus makes content immediately actionable for Dutch security teams implementing AI tools while ensuring regulatory compliance and privacy safeguards.

Relevance 85 · Audience 90

Balancing AI security with privacy and GDPR

16:00 · July 22, 2026

Balancing AI security with privacy and GDPR

Directly addresses GDPR compliance and privacy risks in AI security deployments, offering actionable guidance highly relevant to Dutch and EU organizations. Provides practical recommendations for security and privacy professionals on balancing capabilities with regulatory obligations.

Relevance 85 · Audience 90

Top 10: AI Privacy Tools

10:30 · July 22, 2026

Top 10: AI Privacy Tools

This article is highly relevant for Dutch security and privacy professionals as it provides actionable tooling options to ensure AI deployments comply with strict EU data protection regulations like GDPR and the AI Act. The listed platforms offer practical solutions for mitigating data leakage, managing PII, and securing generative AI workflows in enterprise environments.

Relevance 85 · Audience 90