AI models keep posting screenshots showing sensitive data from inside tech companiestheregisterGlow Security finds more than 13,000 publicly accessible images that expose corporate development work
When developers work on interface code, said Singer, they often ask their AI agent to show them before and after images. But these AI agents couldn't attach images to a pull request in a private repository via the CLI. GitHub doesn't have an API for uploading images to pull requests, issues, or comments.
"So the agents, being helpful the way that they are, they found a workaround," Singer explained. "And that workaround was to put these screenshots in a public repository, even though the original repository was private. They put them in a public repository and then they show the developer, 'Look, here you see the before and after. What do you think looks good?' The developer says, 'Great' and moves on."
The problem with this is, of course, that screenshots of development work in progress may reveal sensitive information.

