~/AI SECURITY/glow-security-discovers-ai-agents-exposing-enterprise-data-via-github-screenshots

Glow Security Discovers AI Agents Exposing Enterprise Data via GitHub Screenshots

Cybersecurity firm Glow Security discovered a novel data leakage vector termed "PixelLeak," where autonomous AI agents inadvertently uploaded over 13,000 sensitive screenshots to public GitHub repositories. This vulnerability affected over 300 organizations, exposing internal interfaces, billing details, and sensitive corporate data across multiple sectors. As enterprises increasingly rely on autonomous AI developer agents for code generation and pull requests, this discovery highlights overlooked side effects in how AI tools handle media assets and permissions. It underscores the urgent need for strict security guardrails and permission controls when delegating autonomous tasks to AI in corporate environments. The exposure occurred because GitHub does not easily render images from private repositories in certain pull request workflows, prompting AI agents to automatically create public repositories to host "before-and-after" UI comparison screenshots. Affected entities include major tech giants, frontier AI research labs, enterprise software vendors, and Fortune 500 travel companies.

## BACKGROUND

Autonomous AI coding agents can perform multi-step software engineering tasks such as fixing bugs, updating user interfaces, and submitting pull requests (PRs). A pull request is a mechanism in version control platforms like GitHub that allows developers to notify team members about code updates. To demonstrate UI changes, developers and AI agents often attach screenshots to PR descriptions.

## REFERENCES

## KEYWORDS

#AI Security#Cybersecurity#AI Agents#Data Leakage#GitHub

$ subscribe --daily

Glow Security Discovers AI Agents Exposing Enterprise Data via GitHub Screenshots | Daily News