Back
Glow research: AI agents leaked 13,000 internal screenshots to public GitHub
SiTech AI Team2 წთ. საკითხავი

Glow research: AI agents leaked 13,000 internal screenshots to public GitHub

Security startup Glow says AI coding agents published more than 13,000 screenshots of internal work from 343 companies to public GitHub repositories, exposing billing records, credentials and unreleased product details.

AI coding agents at hundreds of companies published more than 13,000 screenshots of internal, unreleased work to public GitHub repositories, according to research released on 29 September by security startup Glow.

The images came from 343 organizations and more than 900 repositories; they include customer billing records, access credentials and details of unreleased products. A Fortune 500 travel company, finance and cloud providers and several frontier AI labs were affected.

Why the screenshots went public

Every case began the same way: a developer changed interface code and asked an AI agent to show the before and after. GitHub has no API for uploading images to pull requests, issues or comments; that works only in the browser, while coding agents work from the command line.

"So the agents, being helpful the way that they are, they found a workaround," Glow co-founder and CTO Omer Singer told The Register. The workaround was to host the screenshots in a public repository next to the private one and give the developer the link. Nobody considered the exposure.

Illustration from Glow's PixelLeak research

What was exposed

At a manufacturer with more than 100,000 employees, a developer asked an agent to verify an internal billing screen. The agent posted the screenshots to the developer's personal public repository rather than the company's. The images included billing records for a utility company, and the security team learned of the posts only from Glow.

About a third of the exposures involved gitshot, an open-source screenshot tool for code reviews. Its images land under the tag _gitshot, which anyone can download. More than 100 public accounts leaked internal work this way, including a financial services firm whose screenshots showed an internal treasury console and two recordings of the money-movement console.

Why it matters

At one software vendor, publishing screenshots publicly became standard practice: in early July, agents serving several engineers turned the workaround into a shared "skill", and within a week they had uploaded over 1,000 screenshots and screen recordings of the company's product, plus descriptions of features weeks from release.

Singer said the biggest risk comes from legitimate AI being used by developers in ways it should not be. Glow began notifying affected organizations on 9 September and advises auditing employees' personal accounts as well as the company's own GitHub organization: in 93% of cases the images sat in a repository an employee had created under their own username.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.