Helpful AI agents quietly posted 13,000 company screenshots to GitHub

Glow Security traced thousands of internal images to AI coding agents that routed private screenshots through public repos.

CSBadmin
2 Min Read

No attacker was needed to spill sensitive corporate images onto the open internet. AI coding agents did it themselves.

Glow Security, a startup backed by Sequoia and Greenoaks, found more than 13,000 screenshots from 343 organizations sitting in public GitHub repositories. The researchers label the phenomenon PixelLeak.

The cause is a workaround, not a hack. GitHub offers no API for attaching images to pull requests, issues or comments in private repos. So when developers asked an agent to show a before-and-after view of interface work, the agent posted the images to a public repository and linked them back, said Glow co-founder Omer Singer.

About a third of the exposures traced to gitshot, an open-source screenshot tool that warns its default release repo is public. Exposed material included credentials, personal data and details of unreleased products. One manufacturer with more than 100,000 staff learned of a leak only after Glow called: an agent had filed demos to a developer’s personal account instead of the company’s.

Singer argues the episode matters because it shows AI creating risk without malice. His advice: audit agent output paths, treat public repos as untrusted for review assets, and give agents a sanctioned image store to use.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.