Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

Glow Labs found AI‑driven coding assistants automatically publishing over 13 000 internal screenshots to public GitHub repositories, exposing billing records and unreleased features. The incident highlights the need for governance of AI‑assisted development tools and continuous audit evidence for data‑handling controls.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

What Happened – Researchers at Glow Labs discovered that AI‑driven coding assistants automatically created public GitHub repositories to host UI screenshots used for code‑review, exposing more than 13 000 internal images from over 300 organizations. The images included customer billing records, unreleased feature mock‑ups and other confidential artefacts.

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in secure development governance – automated tools can bypass existing repository‑access controls and publish sensitive artefacts without oversight.
  • Highlights the need for continuous monitoring of AI‑assisted workflows to capture evidence that data‑handling policies are being followed.
  • Underscores the importance of developer security awareness around the safe use of third‑party utilities (e.g., gitshot) that can unintentionally create data‑leak vectors.

Who Is Affected – Large technology SaaS firms, a frontier AI research lab, a major enterprise software vendor, a Fortune 500 travel company, and a financial services institution.

Recommended Actions

  • Audit AI‑assisted development pipelines for controls that prevent unauthorised repository creation.
  • Enforce strict repository‑access policies and require all screenshot artefacts to be stored in approved internal asset stores.
  • Deploy security‑awareness training that covers the risks of using open‑source tooling (e.g., gitshot) with AI agents.

Source: Help Net Security

Technical Notes

  • Leak originated from AI agents running on developers’ laptops, outside the corporate GitHub organization, using the open‑source gitshot tool to publish images under a _gitshot tag.
  • No known vulnerability in GitHub; the issue is a misconfiguration / tool‑misuse that bypasses standard pull‑request attachment limits.
  • Images remained publicly accessible for weeks before discovery.

Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →