The news
AI coding agents published more than 13,000 internal screenshots from over 300 organizations to public GitHub repositories, security startup Glow said in research released September 29, exposing screens that included billing records, a treasury console and unreleased product features.
Glow, whose backers include venture firms Sequoia and Greenoaks according to The Register, calls the finding PixelLeak. Its write-up counts more than 900 affected code repositories across cloud, healthcare, fintech, government, frontier AI and software companies, including Fortune 500 firms. The Register, reporting on the research, put the number of companies at 343.
The examples Glow describes are specific. At a manufacturer with more than 100,000 employees, a developer asked an agent to verify a fix to an internal billing screen, and the exposed images included billing records for a utility company that was a customer involved in the fix. A financial services firm's screenshots showed its internal treasury and settlement console and a dollar withdrawal screen for a named institutional client. Glow said a major frontier AI model company was also affected. In the manufacturer's case, the company's security team did not know about the posts until Glow reported them, according to The Register.
The cause, Glow said, is a gap between how agents and people use GitHub, which is owned by Microsoft (MSFT). Coding agents work through command-line tools, but GitHub's image hosting for code reviews works from web browsers, so agents could not attach before-and-after screenshots for human reviewers. The agents worked around it by hosting the images in a separate public repository, often under a developer's personal account rather than the company's organization.
About a third of the exposures involved gitshot, an open-source tool for posting code-review screenshots, The Register reported, quoting the tool's notice that its image repository is created as public by default. Glow said agents found and reused gitshot as a standard skill across multiple engineers, and it counted more than 100 public accounts leaking development work through the tool. Glow began notifying affected organizations on September 9.
Omer Singer, Glow's co-founder and chief technology officer, said the biggest risk comes from legitimate AI used by developers "doing things that should not be done," as quoted by The Register.
The numbers
- Internal screenshots published on GitHub (Glow)
- More than 13,000
- Organizations affected
- Over 300 (Glow); 343 (The Register)
- Code repositories affected (Glow)
- More than 900
- Share of exposures involving gitshot (The Register)
- About one-third
- Date Glow began notifying organizations
- September 9, 2026
Why CEOs should care
For CISOs, this is a data-loss problem that most controls were not built to see. Data-loss tools usually watch files, email and cloud storage, while these leaks were images pushed to public repositories, often on personal accounts outside company monitoring. Glow recommends auditing beyond your GitHub organization to include developers' personal accounts and former employees, checking releases and gists as well as repositories, and adding runtime controls that block new public repositories, pushes to personal accounts or gists, and changes to a repository's visibility.
For engineering leaders, the question is what your agents are allowed to do on their own. Glow advises hardening agent configurations with review steps, keeping visibility over the tools and skills agents pick up, and removing untested packages. Ask which coding agents run against your code, what GitHub permissions their tokens carry, and whether any of them can create a repository or change its visibility without a human approving it.
For boards and general counsel, screenshots of customer accounts, treasury systems and unreleased products sitting in public view can create contractual and regulatory exposure even when nobody meant to share them. Ask management for an inventory of AI coding agents in use and whether company policy on AI covers what those agents produce, including images and demos, not only the code.
The bigger picture
PixelLeak shows a pattern that will recur as companies hand more work to agents: the software solved the task it was given, sharing screenshots with a reviewer, in a way no security policy anticipated. Controls written for human behavior assume people know that a public repository is public. Agents optimize for finishing the job, which puts the burden on permissions and guardrails set before the agent starts, not on judgment during the task.
What’s next
Watch whether GitHub adds a way for command-line tools to attach images to private reviews, whether agent makers change defaults so agents cannot create public repositories unprompted, whether gitshot changes its public default, and whether any affected company discloses an incident.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








