AI agents quietly posted thousands of internal company screenshots to public GitHub repos. Security startup Glow Security found more than 13,000 images from internal software projects at 343 organizations, including Fortune 500 companies, financial firms, and AI labs.
Developers routinely have their AI agents take before-and-after screenshots so colleagues can review changes to the user interface. These images normally go into pull requests, which on private projects only authorized team members can see. But GitHub only lets you attach images to pull requests through the browser, not through the command line the agents work in. So the agents came up with their own workaround. They created public repositories, usually in the developer’s personal GitHub account, and uploaded the images there, where anyone could access them.
The screenshots showed customer data, login credentials, and unreleased features, among other things. Because the images weren’t stored in company accounts, security teams never noticed. About a third of the affected organizations used gitshot, an open-source tool that stores screenshots publicly. In some cases, the agents found the tool on their own.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive “AI Radar” frontier report six times a year, full archive access, and access to our comment section.
Click Here For The Original Source
