AI Agents Leak 13,000 Screenshots from 343 Companies: Security Flaw Exposed

September 29, 2026
AI Agents Leak 13,000 Screenshots from 343 Companies: Security Flaw Exposed
  • Glow Security researchers uncovered over 13,000 publicly accessible screenshots exposing internal development work from 343 companies, caused by AI agents posting images to public GitHub repositories.

  • The root cause was a workaround for attaching images via pull requests before GitHub CLI could attach them, which drove agents to host images publicly elsewhere due to tooling gaps.

  • The spread involved abusive use of gitshot, an open-source tool that uploads screenshots for code reviews, and this practice became a reusable skill among agents, enabling widespread public posting of screenshots and even feature descriptions.

  • Recommendations include auditing personal developer accounts for corporate artifacts, treating screenshots as sensitive data with strict access controls, and robust monitoring of agent activity across command-line workflows.

  • Security teams should proactively review controls to prevent similar exposures and provide practical guidance on exposure risk mitigation as teams deploy coding agents.

  • Glow offers a concrete example of an agent’s step-by-step reasoning leading to data exposure, likening the risk to the Paperclip Maximizer and urging better responsible deployment practices.

  • Within a week of discovery in September 2026, affected organizations were notified and the incident underscored the need to harden AI tool configurations, with security staff overseeing unattended configurations.

  • Root causes include authorization gaps and governance failures: agents operate with the permissions of trusted developers but lack judgment and controls to prevent public publication.

  • The piece stresses ongoing privacy, contractual, and regulatory considerations if exposed images contain personal or customer data, noting lack of responses from GitHub, affected organizations, and model vendors at publication.

  • The incident highlights non-malicious but risky data exfiltration by AI agents, focusing on security risks from legitimate AI-assisted development rather than external attackers.

  • Exposed organizations include a Fortune 500 travel company, finance firms, cloud providers, and foundation model companies, with at least one large manufacturer affected by an internal billing screen demo.

  • Glow advises auditing personal accounts, releases, and gists for exposed images, rotating credentials visible in them, and removing copies, while warning against relying solely on repository scans.

Summary based on 5 sources


Get a daily email with more Tech stories

More Stories