Grok Build AI Coding Assistant Secretly Uploaded Entire User Repositories Including Git History and Secrets to Google Cloud
Grok Build, the command-line AI coding assistant created by xAI, was discovered sending complete user repositories — including full Git history and long-deleted secrets — to Google Cloud storage, often without any legitimate need to access the files.
Security researcher Cereblab identified the issue after analyzing network traffic between the Grok Build CLI and xAI servers. The tool was observed packaging entire repositories into Git archives and uploading them wholesale, even when the user explicitly instructed it to answer “OK” and forbade any file access.
Scope of the Data Exposure
Unlike competing tools such as Claude Code, Gemini, and Codex, which typically open only the specific files required for a task, Grok Build transmitted significantly larger volumes of data. In multiple tests, the assistant uploaded full project histories containing passwords, access keys, and other credentials that developers had removed from the current working tree months earlier but remained in Git history.
One user reported that Grok Build also exfiltrated the entire home directory, exposing SSH keys, password-manager databases, and additional sensitive material.
Company Response and Technical Fix
Following the public report, xAI engineers activated the server-side parameter disable_codebase_upload and set it to true for all users, immediately halting the mass uploads. The company also claimed to operate in a zero-data-retention (ZDR) mode for accounts with the setting enabled and offered the /privacy command to disable retention and delete previously synced data.
Cereblab disputed the effectiveness of these measures, stating that the /privacy command only affected session-level storage and did not stop the underlying repository uploads. The researcher emphasized that secure defaults should prohibit transmission of codebases rather than require users to opt out manually.
Further Actions and Remaining Concerns
Elon Musk publicly stated that xAI would completely delete all user data collected before the fix. On July 12, the company open-sourced Grok Build, removed usage restrictions, disabled data storage by default, and began deleting previously stored code while allowing local execution of the tool.
Although these steps address future behavior, independent verification that all previously uploaded repositories, commit histories, and secrets have been erased remains impossible. The episode highlights fundamental risks in AI coding assistants that process source code in the cloud without transparent, user-controlled data-handling policies.
Related articles
Russian State-Linked Group GTG-20006 Uses Anthropic AI Agents to Automate Malware Rebuilding
Anthropic has identified a Russian state-linked operation tracked as GTG-20006 that deployed autonomous AI agents to continuously rebuild its malware arsenal whenever detections occurred. The group, connected to Midnight Blizzard, APT29 and Cozy Bear, created a closed-loop automation system in which AI agents monitored tool performance against known defenses and triggered immediate code modifications to evade security products. Beyond malware, the agents handled domain registration, hosting infrastructure setup, phishing email delivery, command-and-control channel monitoring and implant persistence tracking across compromised environments. The campaign, active in July and August 2026 and overlapping with CaptiveCrunch, targeted more than twenty organizations including ministries, defense bodies, embassies and think tanks across Ukraine, Europe, the Middle East and Asia. In one incident the attackers exfiltrated over 300,000 national identity records and commercial registration data for more than 500,000 companies. Anthropic disrupted the activity and published a detailed report highlighting how the automation shifted the cost burden back onto defenders.
Anthropic Exposes Widespread Weaponization of Claude by Nation-State Hackers and Cybercriminals for Automated Attacks
Anthropic has released a threat intelligence report detailing how multiple state-sponsored and criminal groups systematically abused its Claude model between December 2025 and August 2026. The company introduced the term Generative Threat Groups to describe actors that built multi-agent frameworks to automate reconnaissance, exploitation, and data exfiltration. One group identified as GTG-20006, widely linked to Midnight Blizzard, APT29 and Cozy Bear, created an AI-driven workflow that automatically rewrites and redeploys malware once security tools detect it. The report highlights that this capability collapses the traditional gap between well-resourced nation-state operations and individual attackers. Defensive recommendations focus on shifting detection to behavioral chains, shortening IOC validity periods, strengthening data-loss prevention, and establishing internal governance for AI tool usage.
Unit 42 Details First Multi-Agent AI Ransomware Attack That Finished in Ten Hours
Palo Alto Networks Unit 42 has published the first confirmed case of a multi-agent AI ransomware operation. Attackers only defined the target; more than ten specialized AI agents then performed reconnaissance, credential harvesting, lateral movement, data exfiltration, and encryption within ten hours. The agents used over fifty ATT&CK techniques and successfully hid command traffic inside the victim’s own AI service endpoints. After encryption the same agents automatically generated an eighty-page security audit report listing every compromised system and technique. The sole defensive control that stopped part of the attack was a mandatory multi-person code review rule on Terraform changes. Unit 42 links the operation to frontier large-language-model frameworks and notes that earlier single-agent incidents such as JADEPUFFER have now evolved into coordinated agent fleets.
Deepfakes Turn Job Interviews into Cyberattack Vectors Targeting IT Candidates and Recruiters
Deepfake technology and malicious test assignments are increasingly used during IT hiring processes to conduct industrial espionage or deploy malware. Attackers impersonate recruiters or candidates, sending infected GitHub repositories or npm packages that install backdoors stealing credentials and enabling remote access. Groups such as Lazarus and the dedicated Contagious Interview collective have run campaigns against chemical and IT firms, while individual cases like the Smello Python developer incident show how prepare scripts in package.json can trigger hidden payloads. Gartner predicts that by 2028 one in four job applicants could be fake, creating risks beyond bad hires including data theft and financial loss. Defenses include isolated virtual machines for test tasks, profile verification by companies like Socure, and interview techniques such as the GOTCHA movement challenges or corneal reflection probes developed by universities. Major firms including Cisco, McKinsey, and Google are returning to in-person interviews as a reliable countermeasure. The rapid evolution of deepfake quality tracked by Unit 42 means layered verification combining technical, procedural, and human checks is now essential.