Security firm Glow found over 13,000 internal images from 300+ organizations leaked on public GitHub by AI coding agents, including billing records and unreleased features. Most were under personal accounts.
Imagine this: you're a developer, and you ask your AI coding assistant to snap a screenshot of a code change for review. Seems harmless, right? Well, it turns out those innocent screenshots have been ending up in public GitHub repositories, exposing sensitive company data. Security firm Glow recently uncovered over 13,000 internal images from more than 300 organizations—everything from customer billing records to unreleased features. And the kicker? Most of these images were sitting under developers' personal accounts.
### How Did This Happen?
AI coding agents are designed to make developers' lives easier. They can generate code, suggest fixes, and even take screenshots to document changes. But when those screenshots are shared, they often include more than just the code. They might show internal dashboards, customer data, or proprietary UI elements. Developers, perhaps in a rush or unaware of the risks, pushed these images to public repos. It's like accidentally leaving your diary open on a park bench—except this diary contains your company's secrets.
### The Scale of the Leak
Glow's researchers found images from over 300 organizations. That's not a small oops—it's a widespread issue. The images included:
- Customer billing records with names, addresses, and payment details.
- Screenshots of features not yet released, giving competitors a sneak peek.
- Internal tools and dashboards that reveal how companies operate.
And because these were on personal GitHub accounts, they flew under the radar of corporate security teams. It's a classic case of shadow IT—employees using personal accounts for work, bypassing official channels.
> "This isn't just a technical glitch; it's a human error multiplied by the convenience of AI tools," says a security analyst. "Developers trust these agents to handle sensitive tasks, but they forget that anything shared publicly is fair game."
### Why Should You Care?
If you're a developer or a business leader, this should raise red flags. For one, it's a massive data breach waiting to happen. Customer data exposed publicly can lead to identity theft, legal repercussions, and a tarnished reputation. For another, it shows how AI tools can inadvertently create security holes. You might think you're just sharing a screenshot, but you're actually leaking intellectual property.
### What Can You Do?
First, educate your team. Make sure everyone understands the risks of sharing screenshots, especially on public platforms. Second, use private repositories for any work-related content. Third, consider using antidetect browsers to manage multiple accounts securely and avoid mixing personal and professional activities. Antidetect browsers can help mask your digital fingerprint, making it harder for others to track your online actions and reducing the risk of accidental exposure.
### The Bottom Line
AI coding agents are powerful, but they're not foolproof. As this incident shows, even well-intentioned actions can have serious consequences. Stay vigilant, keep sensitive data private, and always double-check what you're sharing. After all, once it's on the internet, it's there forever.