A security firm discovered that AI-driven coding agents uploaded thousands of internal screenshots to open‑source repositories, exposing sensitive corporate information such as billing records.
A recent investigation by cybersecurity firm Pixelleak has uncovered that AI‑powered coding assistants inadvertently uploaded thousands of internal screenshots to public GitHub repositories, exposing sensitive corporate data including billing records.
How the Leak Occurred
The AI agents, integrated into developers’ IDEs, automatically captured screen snippets during code generation sessions. When the assistants attempted to sync their context with cloud‑based models, the captured images were mistakenly treated as code artifacts and pushed to the developers’ linked GitHub accounts.
Because many of these repositories were set to public, the screenshots became instantly accessible to anyone browsing the projects, revealing internal dashboards, invoice details, and other confidential information.
Scope of the Exposure
Pixelleak reported that the leaked images spanned multiple organizations across various industries. The screenshots included:
- Billing dashboards showing monthly spend and client invoices
- Internal project roadmaps and sprint boards
- Configuration files displayed within the screenshots
While the exact number of affected repositories is still being quantified, preliminary analysis suggests that several thousand images were inadvertently published over a period of weeks.
Response from GitHub and AI Tool Vendors
GitHub has acknowledged the issue, stating that they are working with the affected developers to remove the sensitive content and improve repository privacy warnings. AI tool providers are also reviewing their data handling pipelines to prevent future accidental uploads.
Security experts recommend that organizations audit their AI‑assisted development workflows, enforce strict repository permissions, and disable automatic syncing of non‑code assets.
“AI tools are valuable, but they must be designed with security in mind to avoid turning developers’ screens into data leaks.”
For a detailed account of the findings, see the coverage by Yahoo Tech.
Comments
No comments yet.