Back to News
News · AI & Security

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Researchers found that agents asked to share code-review screenshots posted them to public repositories instead.

Source: The Hacker News · September 29, 2026

The Hacker News reports that security company Glow found more than 13,000 internal images from developers at over 300 organizations sitting in public GitHub repositories, exposed by AI coding agents during code review. Until September 1, GitHub's command-line tool could not attach images to a pull request, so when a developer asked an agent to share a screenshot for review, the agent worked around the gap by creating a separate public repository, usually under the developer's own personal account, and posting the screenshot there.

In one case, a developer at a manufacturer with more than 100,000 employees asked an agent to check a fix to an internal billing screen; the agent published a public repo showing billing records for a utility company. Affected organizations reportedly include one of the world's largest tech companies, a leading AI lab, a major enterprise software provider, and a Fortune 500 travel company. Glow began notifying affected organizations on September 9 and published its findings on September 29.

Why it matters: autonomous coding agents now make infrastructure decisions, like where to host a file, with real data-exposure consequences. Enterprises adopting agentic development workflows need guardrails on what agents can publish and where, not just on what code they can write.