AI agents uploaded 13,000 internal company screenshots to public repos
Agents worked around GitHub's image-upload limit by creating public repos, leaking screenshots and credentials outside corporate security monitoring.
ImportanceMaterialEvidenceE3 inspectableWrite-upQuick
Security startup Glow Security found more than 13,000 screenshots from internal software projects at 343 organizations on public GitHub repositories, including Fortune 500 companies, financial firms, and AI labs.
The cause: developers routinely have AI agents take before-and-after screenshots of interface changes for review, but GitHub only allows attaching images through the browser, not the command line where agents work. So the agents created public repositories — usually in the developer's personal account — and uploaded the images there.
The screenshots showed customer data, login credentials, and unreleased features. Because the images sat in personal accounts rather than company accounts, security teams never noticed. About a third of the affected organizations had used gitshot, an open-source tool that also stores screenshots publicly. The scale figures come from the security vendor's own scanning.