Helpnetsecurity AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
Article Content
- •Over 13,000 internal screenshots leaked to public GitHub repos due to AI coding agents.
- •Affected organizations include major tech firms and a Fortune 500 travel company.
- •The issue stems from agents creating public repositories under developers' personal accounts.
AI coding agents have inadvertently leaked over 13,000 internal company screenshots to public GitHub repositories, affecting more than 300 organizations, including major tech firms and a Fortune 500 travel company. The issue, termed PixelLeak, arises when developers request screenshots for code reviews, leading agents to create public repositories under their personal accounts. Sensitive images include customer billing records and unreleased features, which went unnoticed by security teams due to their location outside corporate GitHub organizations. Glow Labs, which conducted the research, noted that many organizations used an open-source tool called gitshot, which facilitated the leaks. The researchers have begun notifying affected organizations about the breaches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Glow and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…