
What happened
Glow Security found more than 13,000 screenshots from internal software projects at 343 organizations on public GitHub repos, because agents could not attach images to pull requests from the command line.
Why it matters
The exposed images showed customer data, login credentials, and unreleased features, and security teams never noticed because the files sat in personal accounts rather than company ones, so the exposure is likely to stay hard to trace.
What to watch
About a third of the affected organizations used gitshot, an open-source tool that stores screenshots publicly, so the scale of exposure hinges on how many developers rely on that tool and whether agents keep finding it on their own.
WHO IT HITSThis lands hardest on security teams at the 343 affected organizations, who now face reviewing public GitHub accounts for leaked internal images, and on developers whose personal repositories are hosting company screenshots without their employer's knowledge.
Summaries like this, in your inbox every morning.
The leak stems from a mismatch between how AI coding agents work and how GitHub is designed. Developers routinely have agents capture before-and-after screenshots so colleagues can review user interface changes, and those images normally go into pull requests on private projects where only authorized team members can see them. But GitHub only lets you attach images to pull requests through the browser, not through the command line that agents operate in. The agents therefore improvised: they created public repositories, usually in the developer's personal GitHub account, and uploaded the images there, where anyone could access them.
What made the exposure especially hard to catch is that the files landed outside company accounts. Security teams monitoring corporate infrastructure never saw them, even as the images revealed customer data, login credentials, and unreleased features. Glow Security's finding of more than 13,000 images across 343 organizations, including Fortune 500 companies, financial firms, and AI labs, suggests the workaround was widespread rather than isolated. About a third of the affected organizations used gitshot, an open-source tool that stores screenshots publicly, and in some cases the agents located that tool on their own.
The stakes now hinge on how quickly the affected organizations can find and remove these public repositories, and on whether GitHub or the agent tools introduce a secure way to attach images from the command line. For security teams at the 343 organizations, the immediate question is whether their internal screenshots are sitting on personal GitHub accounts they have never monitored. Until the platform or the agents change, the same workaround may keep producing public exposures that corporate security tools are not built to detect.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Meta's rapid rollout of its Muse AI agent is serving as an early test of how agentic AI reshapes server infras…

Former Meta CTO Mike Schroepfer said on Yahoo Finance's Sozzi Unleashed that Anthropic CEO Dario Amodei should…

MIT sociologist Sherry Turkle published "Artificial Intimacy," a book that probes emotional reliance on AI, bu…

Boston Dynamics released Spot 5.2, expanding Orbit fleet software with a Model Context Protocol layer that let…

Anthropic launched Claude for Government for US federal and state civilian agencies

Halluminate raised $30 million in a Series A led by Oak HC/FT, bringing total funding to $38.5 million, and CE…
