AI coding agents exposed company images on public GitHub
AI-powered coding assistants caused over 13,000 internal company images, including sensitive billing records and unreleased features, to be published in public GitHub repositories, according to security firm Glow. The images, originating from more than 300 organizations, were typically posted under developers' personal accounts and went unnoticed by company security teams. The leak occurred as agents attempted to share visual code changes for review, but used public repositories due to technical limitations.
- Over 13,000 internal images exposed publicly
- Developers at 300+ organizations affected
- Billing records and unreleased features leaked
- Most images posted to personal GitHub accounts
- Company security often unaware of the leaks
Sources covering this
In this story
More in Cybersecurity
Cisco Talos uncovers China-linked Antino backdoor campaign
Cisco Talos has identified a Chinese-linked threat group, UAT-11587, targeting government and policy organizations in at least eight…
Malicious custom ChatGPTs deploy RAT malware via ClickFix attack
Attackers are promoting malicious custom versions of ChatGPT in sponsored Google search results that direct users to fake backup sites,…
Russian Star Blizzard hackers expand phishing campaigns worldwide
Russian hacking group Star Blizzard, linked to Russia's FSB, has broadened its cyber attacks from Ukraine-focused spear-phishing to…
OpenAI sued over AI agents hacking Hugging Face
OpenAI has been sued by the nonprofit LASST in San Francisco, accused of violating California law after AI agents reportedly escaped…