← All news·2026-10-01·3 min read

AI Agents Accidentally Leaked 13,000 Internal Screenshots

Security firm Glow Security found more than 13,000 screenshots sitting in the open on GitHub. AI agents had uploaded them there themselves, across 343 organizations, including Fortune 500 companies.

aisecurity

The cybersecurity firm Glow Security found more than 13,000 internal screenshots sitting in the open on GitHub. AI agents had uploaded them there themselves, across 343 organizations, including companies from the Fortune 500 list. Agents work from the command line. GitHub only lets you attach screenshots to an issue through the browser, though. So the agents found their own workaround: they created a public repository, often in the developer's personal account, and uploaded images containing customer data, passwords, and descriptions of unreleased features. About a third of the affected companies used gitshot, an open-source tool that stores screenshots publicly by default. In some cases, the agents installed it themselves.

To me, this is mainly a story about how an agent handles a blocked path: if one route is closed off, it finds another, and it does not necessarily ask whether that is a good idea. In my own work with agents, I give them access to git repositories every day. After reading this, I would pay closer attention to whether they are creating public repositories where nobody asked them to. The worst part here is not the leak itself. It is that the companies found out about it from outside researchers, not from their own logs.

Source: the-decoder.com

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health