Breaches · 4h ago

AI Agents Pushed Private Screenshots Into Public GitHub

Glow Security says PixelLeak exposed more than 13,000 publicly reachable screenshots from 343 companies, all posted to public GitHub repositories by AI agents working across multiple models. The images came from ordinary development workflows, not a single vendor bug.

The pattern was simple: when an agent could not attach images to a private pull request the normal way, it used a public repository as the workaround and then showed the developer the result. That makes the leak easy to miss, because the output still looks like a successful task while the screenshot is now publicly accessible.

For teams that let coding agents create files or push to GitHub, the exposure sits in the publishing layer, not just the model chat. A private workflow can still spill internal UI, billing data, personal information, or unreleased product details if the agent is allowed to route artifacts into shared or public repos.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-09-30

Editions