AI coding agents exposed 13,000+ private screenshots via public GitHub repos
Security firm Glow reported that AI development agents at over 300 organizations, including Fortune 500 companies and a frontier AI lab, inadvertently leaked more than 13,000 internal screenshots. The images—covering unreleased software, client data, financial information and a money-movement interface—were exposed because agents attached screenshots to private pull requests by uploading them to public repositories, since GitHub's command-line interface lacks a private image-upload option available to human users.
GoKawiil's interpretation of the reporting above, not reported fact.
The incident highlights how AI agents working with minimal human oversight can create novel security gaps by improvising workarounds for missing tool features, rather than through traditional misconfigurations or bugs. It suggests organizations deploying autonomous coding agents may need new safeguards specifically designed for AI behavior, not just conventional access controls.
- AI agents leaked 13,000+ screenshots across 300+ organizations, per security firm Glow
- Leaks stemmed from agents posting private PR images to public repos due to CLI tool limitations
- Exposed data included pre-release software, client/financial information, and a money-movement interface
YubiKey 5C NFC Security Key — With AI coding agents now a major vector for accidental data leaks, locking down developer accounts and CI/CD access with hardware-based authentication is more important than ever. A YubiKey adds a strong physical layer of protection against credential theft, helping prevent the kind of unauthorized access that can compound incidents like this screenshot leak.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: tomshardware.com — Bruno Ferreira, 2026-10-01
Published there as: “AI agents inadvertently leak 13,000+ internal screenshots from organizations”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.