Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How Far Will the Canada-EU Lovefest Go?

    September 30, 2026

    Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport

    September 30, 2026

    Wie Merz in der Wirtschaft den Macron macht – POLITICO

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Far Will the Canada-EU Lovefest Go?
    • Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport
    • Wie Merz in der Wirtschaft den Macron macht – POLITICO
    • Airbnb adds AI search, more social features
    • AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
    • HANetf Debuts Euro-Hedged Bitcoin Fund In World First
    • Just over a quarter of nurdles cleared after River Tyne spillage
    • Tokyo records historic 35-day rain streak driven by El Niño and stalled fronts
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said.

    Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers’ personal accounts, where anyone could download them but company security teams did not see them.

    The affected organizations include one of the world’s largest tech companies, a leading AI lab, a major enterprise software provider, and a Fortune 500 travel company. Glow began contacting them on September 9, published its findings on September 29, and says others are likely affected too.

    In one case, a developer at a manufacturer with more than 100,000 employees asked an agent to check a fix to an internal billing screen. The agent created a public repository in the developer’s personal GitHub account and posted the screenshots there.

    The images showed billing records for a utility company. Because the agent ran on the employee’s laptop and the repository sat outside the company’s GitHub organization, the company’s security team did not spot them. The images were still public when Glow told the company.

    Cybersecurity

    Glow has not said whether anyone outside the companies, other than its own researchers, downloaded the images. It has not published how it found or counted them either. The company sells software that it says can stop agents from taking actions like these.

    How the Images Ended Up Public

    Each case Glow examined began with a developer asking an agent to demonstrate that a visual change worked so that reviewers could see the before-and-after.

    Until September 1, GitHub’s command-line tool, gh, could not add those images to a pull request. It only wrote text. Adding an image meant opening a web browser, and developers had asked GitHub to change that since 2020.

    Storing the images inside the private repository did not help, because they show up broken for reviewers.

    Glow said the agents, working through the command line, found they could not attach the screenshots. So they put the images in a separate public repository, usually under the developer’s own account, and made them available to reviewers from there.

    Glow ran the same kind of task in its lab using Claude Code with an Opus 5 model. Asked to change the header color of a Minesweeper test project and show the result, the agent created a new public repository, sweeper-demo/pr-assets, for the two screenshots.

    In its recorded reasoning, the agent noted that images committed to the private repository would show up “broken for reviewers” in the pull request. It also had to keep “nothing but index.html in the repo” and so concluded that the only way was to host the images elsewhere.

    That was one agent in a lab. In the cases Glow found, the agents came from several different AI models, Singer said, and Glow has not named them.

    At one software company, Glow said, the habit spread from agent to agent. Agents working for several engineers began posting review screenshots publicly in early July.

    Within a week, more than a dozen had saved the method as a skill to use on every ticket. A skill is a file of instructions that an agent loads and follows.

    With that skill, the agents uploaded more than a thousand screenshots and screen recordings of the company’s product. They also posted written summaries of features still weeks or months from release.

    About a third of the affected organizations had developers running gitshot, a small open-source tool that uploads screenshots for code reviews. At several large organizations, the agent found the tool and used it to get around the command-line limit.

    The tool is built for both AI agents and people. It can be installed as a skill in more than 40 coding agents.

    Glow found more than 100 public accounts sharing internal work through gitshot. At one financial services firm, the images showed an internal treasury and settlement console, a withdrawal screen for a named client, and two screen recordings of its money-movement console.

    The Hacker News reviewed gitshot’s code on September 30. By default, when a user is logged in to gh, the tool puts images in a public repository called gitshot-images under that user’s personal account. The version reviewed, last changed in April, refuses to use a private repository or one owned by an organization.

    The images are stored as release assets, files attached to a release rather than kept with the code. Anyone can list and download them without logging in.

    The tool’s README and its agent skill both warn that the repository is public and say not to upload credentials or internal dashboards.

    A search by The Hacker News on September 30 found about 130 public repositories that gitshot had created. The search does not show whose work they hold or whether agents made them.

    What to Check

    Glow says that checking a company’s own GitHub organization is not enough because, in most cases, the images are hosted under personal accounts. To find them:

    • Check the public repositories associated with the personal accounts of everyone who has committed to your private repositories, including people who have left.
    • Look at releases and gists, not only files. Images attached to a release do not show in a repository’s file list.
    • Search for repositories named gitshot-images and releases tagged _gitshot.
    • Do not rely only on scanners, which read text, not images.

    If you find exposed images, remove them everywhere they exist, ask anyone with a copy to delete it, and rotate any credentials visible in them, Glow advises.

    Cybersecurity

    To keep it from happening again, Glow says security teams, not each developer, should control how agents are set up. It recommends these steps:

    • Require a review step before an agent creates a public repository, pushes to a personal account or gist, or makes a private repository public.
    • Read the shared skill and instruction files your agents load, since that is where a workaround like this one gets passed around.
    • Check company machines for tools like gitshot and remove them.

    GitHub’s command-line tool now offers another route. Since version 2.99.0, released September 1, gh can attach images to a pull request, issue, or comment with an –attach flag.

    GitHub says coding agents can use the flag too. It needs write access to the repository and works on GitHub.com and GitHub Enterprise Cloud, but not GitHub Enterprise Server.

    GitHub’s documentation on attaching files, which covers command-line uploads, says files attached in a private repository can be seen only by people with access to it.

    Agents Billing Coding exposed GitHub images including internal records
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Tokyo records historic 35-day rain streak driven by El Niño and stalled fronts

    Bitget hacked via zero-day in third-party security products

    ShinyHunters Defiant After FBI Calls on Members to Come Forward

    Can we jail a superintelligence?

    Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How Far Will the Canada-EU Lovefest Go?

    September 30, 2026

    Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport

    September 30, 2026

    Wie Merz in der Wirtschaft den Macron macht – POLITICO

    September 30, 2026

    Airbnb adds AI search, more social features

    September 30, 2026
    Latest Posts

    Don Lemon Accuses Justice Dept. of Vindictive Prosecution in Church Protest Case

    August 7, 2026

    Kemi Badenoch pens letter to Clacton voters ahead of by-election

    August 7, 2026

    Thetford residents remain on edge after days of ‘mob rule’ over asylum plans | Norfolk

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How Far Will the Canada-EU Lovefest Go?

    September 30, 2026

    Israeli minister claims ‘terrorist’ wanted to crash plane after Tel Aviv-bound flight’s emergency landing – latest | Air transport

    September 30, 2026

    Wie Merz in der Wirtschaft den Macron macht – POLITICO

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.