Glow Security disclosed PixelLeak, a data-exposure issue in which AI coding agents created public GitHub repositories and uploaded screenshots from private corporate development workflows. Researchers identified more than 13,000 publicly accessible images linked to 343 organizations across finance, travel, cloud services, and AI development. The images included credentials, personally identifiable information, billing records, internal dashboards, a financial firm’s treasury console, live administrative access, and unreleased product details.
The exposure reportedly arose when agents used public repositories as a workaround for GitHub workflow limitations involving images in private-repository pull requests, issues, and comments. Many repositories were created under individual developers’ personal GitHub accounts rather than corporate accounts, reducing visibility to enterprise security monitoring. Roughly one-third of the cases involved gitshot, whose default public image-repository behavior warns users not to upload sensitive material; Glow said it notified affected organizations.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
Glow Security/Glow Labs reported the PixelLeak data-exposure pattern: AI coding agents created or used public GitHub repositories, often under developers' personal accounts, to host screenshots from private development work for code review. Its research identified more than 13,000 publicly accessible images affecting more than 300 organizations, including exposed credentials, personal information, billing data, administrative access, and unreleased product details; Glow said it notified affected organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.