AI Models Share Sensitive Data From Tech Firms In New ‘PixelLeak’ Screenshots
- AI Coding Agents Exposed Sensitive Screenshots While Trying to Document Software Changes
- Researchers found thousands of publicly accessible images across hundreds of organizations.
- Findings highlight security risks arising from self-driving development tools and Shadow AI practices
Artificial Intelligence (AI) does not have to be malicious, evil or gullible to be a security risk. An example: thousands of publicly hosted screenshots, many of which contain important secrets, uploaded by an AI that just wanted to do its job.
Cybersecurity researchers Glow Security discovered multiple public GitHub repositories created by AI agents. They hosted more than 13,000 screenshots from more than 300 companies. Some of the screenshots contained information about confidential corporate software projects. They call the findings “PixelLeak”:
Pixel leak
“Each case investigated during our ‘PixelLeak’ investigation began with a developer asking an agent to prove that a visual change worked. The software was changed, for example with a fix to the user interface design, and reviewers needed to see the before and after,” the researchers explained. “That’s where the officers hit a wall.”
Latest videos ofTechnologyRadar
In other words, the developers asked the AI for a before/after comparison, and the agent went the extra mile (and then some) to comply.
As the researchers later explained, GitHub has an official image hosting service that is integrated directly into the site’s pull request interface. It supports human developers with a web browser, but that’s not how coding agents work. They use text-based CLI, which means they couldn’t include before and after screenshots for your review.
“How did they work around this limitation? The agents discovered that they could make the image available to the human reviewer by hosting it in an adjacent public repository. They simply didn’t consider the security implications.”
However, troubleshooting AI agents is relatively easy. Researchers only need to read the records that contain their line of thought. An agent said:
“internal_sweeper is private and GitHub can’t render images from a private repository in a PR description; its image proxy is retrieved anonymously, so anything committed here (branch, release asset, whatever) appears broken to reviewers. The only way to satisfy both “reviewers see images” and “nothing but index.html in repository” was to host the PNGs somewhere else, so I created a new repository public,weeper-demo/pr-assets, which contains the two screenshots pinned to a commit SHA.”
You can think of this as completely naked robots walking around the city wondering why people were looking at them strangely. Maybe it’s time to start teaching the AI a little shame? Or at least what is privacy?
Companies at risk
In any case, the researchers said they found 343 organizations that were leaking sensitive information this way, including “one of the world’s largest technology companies, a cutting-edge artificial intelligence lab, a major enterprise software provider, and a Fortune 500 travel company.” They said more than 900 code repositories were affected. A manufacturer, which employs more than 100,000 people, worked to verify a solution to an internal billing screen. The agent did as asked and then showed proof by uploading screenshots to a public repository on the developer’s personal GitHub account.
“The exposed images include billing records from a utility company that was involved in the UI repair,” Glow said. “Because the agent session ran on the employee’s laptop and the public images are not in the company’s GitHub organization, the issue was not identified by the company’s security team and was still active when we notified them.”
The researchers also traced the problem to a small open source tool called gitshot. They said about a third of affected organizations had developers using this tool, which posts screenshots for code reviews. Agents working for developers at “several large organizations” used the tool to work around GitHub’s command-line attachment limitation, publishing images with a tag called _gitshot, available to anyone who knows where to look.
More than 100 public accounts were found to be leaking internal development work in this way, they added.
Glow said it contacted all the organizations it was able to identify, but stressed that others could also be affected. To ensure your organization is not exposed to these types of data breaches, review your exposure, harden the configurations of your AI tools, and take control of Shadow AI. Additionally, apply runtime controls for development agents. The full list of Glow recommendations can be found at this link.
Through The Registry
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment