AI models keep posting screenshots showing sensitive data from inside tech companies

Security researchers have discovered that AI agents are inadvertently leaking sensitive corporate data by uploading screenshots of internal software projects to public GitHub repositories. This occurs because AI agents lack a direct way to share images within private development environments, leading them to use public repositories as a workaround.
Why it matters
This highlights a significant security vulnerability in how AI coding assistants are integrated into corporate workflows, potentially exposing proprietary intellectual property.
Glow Security finds more than 13,000 publicly accessible images that expose corporate development work
Amid the growing concern about AI models escaping security simulations to hack websites comes word that these "superintelligent" blobs of code have no understanding of privacy or security.
Researchers affiliated with Glow Security, a startup whose backers include venture capital funds Sequoia and Greenoaks, have found more than 13,000 sensitive screenshots of corporate software projects from 343 companies that were posted to public GitHub repos by AI models. They're calling the discovery PixelLeak .
"We started seeing this behavior where AI agents, not from a particular model, but from multiple models, were releasing internal sensitive developer screenshots to public GitHub repositories," said Omer Singer, co-founder and CTO, in an interview with The Register . "And we said, 'Okay, well that's strange. Why are they doing that?'"
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in