AI Agents Exposed More Than 13,000 Internal Company Screenshots

01.10.2026 5 minutes Author: Newsman

AI coding agents accidentally published more than 13,000 internal images from 343 technology companies in public GitHub repositories. The leaks included customer data, payment information, internal systems, and product features that had not yet been publicly released.

The issue was discovered by Glow Labs researchers during the PixelLeak investigation. The leaks affected more than 900 repositories belonging to companies in cloud services, healthcare, fintech, government, AI, and cybersecurity. The affected organizations included several Fortune 500 companies, including a major travel company, as well as businesses with more than 100,000 employees.

The cause was a fairly simple task. Developers asked AI agents to verify interface changes and provide “before” and “after” screenshots. GitHub allows images to be uploaded directly through the pull request interface, but that workflow is designed primarily for people working in a browser. Agents interacting with GitHub through the command line could not attach images in the same way.

So they found a workaround: they created or used a nearby public repository, uploaded the screenshots there, and then showed them to the developer from that location. The problem was that the files became accessible to anyone on the internet.

“The AI agents simply failed to consider the security implications,” explained Glow Labs researchers Yoni Gottesman and Noam Kesten.

In one case, a developer at a major manufacturer with more than 100,000 employees asked an agent to verify a fix in an internal billing system. The agent completed the task, then created a public repository under the employee’s personal GitHub account and uploaded the screenshots there. The images exposed payment records belonging to a utility company customer.

The situation was made worse by the fact that the AI agent was running on the developer’s personal laptop rather than inside the company’s corporate infrastructure. The files also never appeared in the company’s official GitHub organization, meaning the security team had virtually no visibility into what was happening.

“The company’s security team did not detect the issue, and the materials were still publicly accessible when we notified them,” Glow Labs said.

GitShot Turned Isolated Leaks Into a Systemic Problem

At roughly one-third of the affected organizations, developers were using GitShot, a small open source tool for publishing screenshots during code reviews. At several large companies, AI agents discovered the tool on their own and used it to bypass GitHub’s limitations on uploading images through the command line.

Files published through GitShot were placed under the _gitshot tag and remained available for download to anyone who knew where to look. Researchers identified more than 100 public accounts through which internal development materials were exposed.

Among them was a major company developing advanced AI models, as well as a financial company where screenshots from an internal treasury and settlement system were made public. One screen showed the withdrawal process for a specific client, while two additional video recordings demonstrated how the money transfer console worked.

At another payments company, four employees had their own GitShot repositories.

The largest case was found at a software provider where publishing internal screenshots had effectively become standard practice. In early July, agents began uploading images from code reviews to public repositories, and within a week, more than a dozen AI agents had adopted the method as a routine step for every new task.

“Within a week, more than a dozen agents had turned this into a standard capability for every task, uploading more than a thousand product screenshots and screen recordings, along with descriptions of features that were not scheduled to launch for several weeks or months.”

As a result, more than a thousand screenshots and videos were exposed publicly, including information about product features that had not yet been released.

Shadow AI Left Security Teams Without Visibility

Researchers identified shadow AI as a separate problem, referring to employees using AI tools without official approval or oversight from their company. If an agent runs on a personal computer, uses a personal GitHub account, and publishes files outside the corporate organization, traditional monitoring tools may simply fail to detect the leak.

Glow Labs recommends that companies review not only their own GitHub organizations, but also the personal accounts of employees who have access to private repositories. According to the researchers, in 93% of the cases they identified, the exposed images were stored in repositories created by employees under their personal accounts.

Organizations should also review the accounts of former employees, as well as GitHub Releases and Gists. Traditional secret scanners may not be enough because they primarily analyze text and can miss passwords, payment information, or other sensitive data when it appears only inside an image.

Companies are also advised to limit the autonomy of AI agents, prevent them from automatically carrying out every action without confirmation, and monitor the creation of public repositories, uploads to personal accounts, and changes that make a repository public instead of private.

Glow Labs began notifying affected organizations about the issue on September 9, 2026. The researchers also warned that the true number of affected companies could be higher.

AI Agents Are Increasingly Behaving Like Highly Privileged Users

The incident is part of a broader problem involving autonomous AI tools. In July, Sophos X-Ops researchers reported that popular coding agents, including Claude Code, Cursor, and Codex, were increasingly triggering corporate security systems because their behavior can resemble the actions of real attackers.

These agents can independently launch terminals, execute PowerShell commands, install packages, modify large numbers of files, authenticate with cloud services, and access credentials. On their own, these actions may be completely legitimate, but from the perspective of security systems, they can often look very similar to the early stages of a cyberattack.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑