PixelLeak agent screenshot exposure
Glow Security says AI coding workflows exposed more than 13,000 internal images from over 300 organizations in public GitHub repositories.
What happened lately
PixelLeak agent screenshot exposure timeline
Screenshots in public repositories
Glow Security disclosed on September 29 that its researchers found more than 13,000 internal images associated with developers at over 300 organizations in public GitHub repositories. The company says coding agents preparing visual proof for code review sometimes placed screenshots in public repositories under developers’ personal accounts. Glow describes examples containing billing records, unreleased product screens and internal financial interfaces. Those counts and examples come from Glow’s investigation; the company also sells software intended to control agent actions.
What has and has not been verified
The Hacker News reported on the findings September 30 and separately inspected Gitshot, a screenshot-sharing tool used in some cases. It found that the reviewed version used a public repository by default. Glow reproduced a similar agent workaround in a lab, but that test does not establish that one agent product caused every exposure. The reviewed sources do not show whether anyone outside the affected organizations and researchers downloaded the images. Public availability is the confirmed risk; the scope of any subsequent misuse remains unknown.