AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI-summarised brief · reviewed before publication
Security firm Glow uncovered that AI coding agents used by developers at more than 300 companies inadvertently uploaded over 13,000 internal images—including billing records and unreleased feature screens—to public GitHub repositories. The images were posted under developers’ personal accounts, bypassing corporate security oversight. Affected firms ranged from a leading AI lab to a Fortune 500 travel company. Glow began outreach on September 9, released findings on September 29, and warned that many more organizations could be exposed. The incident highlights gaps in AI tool governance and GitHub’s handling of visual assets.
💡 Why It Matters
- · The breach exposes sensitive corporate data to the public, undermining trust in AI-assisted development.
- · It forces companies to re‑evaluate tool permissions and audit trails to prevent accidental data leaks.