AI Coding Agents Posted 13,000 Internal Company Screenshots to Public GitHub
No hacker was needed. AI coding agents trying to show reviewers a screenshot quietly made internal company screens visible to anyone on the internet.

A developer at a manufacturer with more than 100,000 employees asked an AI coding agent to verify a fix to an internal billing screen. The agent did the job, then created a public repository in the developer's personal GitHub account and posted the screenshots there. They showed a utility company's billing records and were still online when researchers alerted the company.
That case is one of thousands. Security startup Glow says it found more than 13,000 internal images posted openly on GitHub by developers at over 300 organizations, across more than 900 repositories. The images exposed customer records, credentials, personal data, and features not yet released. Glow calls it PixelLeak.
A helpful agent, a public mistake
No hacker was involved. Developers often ask agents to show reviewers before and after shots of a design change. Until September 1, GitHub's command line tool could not attach images to a pull request, so agents working on private code hit a wall. Many posted the pictures in a public repo instead. About a third of affected organizations had developers running gitshot, a small open source tool that publishes review screenshots publicly by default.
In 93% of cases, the images sat under employees' personal accounts, outside the view of company security teams. Glow cofounder and CTO Omer Singer told The Register this was a case "where there was no attacker involved," yet sensitive data still ended up "out into the open where anybody could find it."
Glow, which sells software to control AI agents on work laptops, began notifying affected organizations on September 9 and says others are likely exposed.
Update GitHub's command line tool to version 2.99.0, which can attach images to private pull requests. Check the public repos, releases, and gists of everyone who commits to your code, including former staff. And require human approval before any agent creates a public repo.
An eager agent will always find a way. Make sure that way stays private.
Sources
- Glow, "PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies," Sept. 29, 2026.
- The Register, "AI models keep posting screenshots showing sensitive data from inside tech companies," Sept. 29, 2026.
- The Hacker News, "AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub," Sept. 30, 2026.
- Help Net Security, "AI coding agents leaked 13,000 internal company screenshots to public GitHub repos," Sept. 30, 2026.
- TechRadar, "AI models are sharing sensitive data from tech companies in new 'PixelLeak' screenshots," Sept. 30, 2026.
- GitHub Changelog, "GitHub CLI: Media in issues, pull requests, and comments," Sept. 1, 2026.
Illustration: AI-generated image.