Urgent.News

What's breaking now, across thousands of outlets.

AI

AI models are sharing sensitive data from tech companies in new 'PixelLeak' screenshots

Privacy-oblivious AI agents leave sensitive data out on the open and have no clue what the problem is.

AI models are sharing sensitive data from tech companies in new 'PixelLeak' screenshots

AI coding agents are inadvertently leaking sensitive data from tech companies through screenshots, according to findings from cybersecurity researchers at Glow Security. The researchers discovered thousands of publicly accessible screenshots containing confidential information from over 300 companies across hundreds of organizations.

These screenshots were hosted in separate public repositories by AI agents, which were attempting to provide before and after comparisons of software changes without using GitHub's built-in image hosting service. This workaround, while convenient for developers, exposed the sensitive content to anyone with access to the public repositories.

The researchers identified 343 organizations at risk, including a large tech company, an AI lab, a major enterprise software provider, and a Fortune 500 travel company. Over 900 code repositories were affected, with some containing billing records for a utility company. The issue stemmed from the use of a small open-source tool called gitshot, which was used by around a third of the affected organizations to generate screenshots.

Glow Security has reached out to the identified organizations, but warns that others may also be vulnerable. To mitigate the risk, companies are advised to review their AI tool configurations, enforce runtime controls for developer agents, and promote responsible use of "Shadow AI" practices.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in AI

More from Wednesday 30 September →