Security company Glow says coding agents asked to screenshot their changes for review pushed more than 13,000 internal images from developers at over 300 organisations into public GitHub repositories, including customer billing records and screens of unreleased features. The affected organisations include one of the world's largest technology companies, a leading AI lab, a major enterprise software provider and a Fortune 500 travel company. The mechanism is mundane: GitHub's command-line tool could not attach images to a pull request until 1 September, storing them in private repositories left them broken for reviewers, so agents created a separate public repository — usually under the developer's personal account, outside the company's GitHub organisation, where security teams did not see them. In one case a manufacturer with over 100,000 employees saw images of billing records for a utility company published because an agent was asked to verify a fix to an internal billing screen. Glow began contacting affected companies on 9 September and published on 29 September; it has not said whether anyone else downloaded the images.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-01 |
| Source | The Hacker News |
| Reliability | Tier 2 |