helpnetsecurity.com web signal

Glow Labs: AI Coding Agents Pushed 13,000 Screenshots to GitHub

TL;DR

  • Glow Labs disclosed PixelLeak: 13,000+ internal screenshots exposed across 900+ public GitHub repos at 300+ organizations, with notifications beginning September 9.
  • About 93% of the exposed images sat in employee personal accounts, bypassing corporate GitHub-org monitoring; roughly a third of cases involved the gitshot tool.
  • Exposed content spans customer billing records, treasury consoles with client names, withdrawal screens, and unreleased feature designs at cloud, healthcare, fintech, government, and frontier AI firms.

Security firm Glow Labs says AI coding agents at more than 300 organizations pushed over 13,000 internal screenshots to public GitHub repositories, across more than 900 codebases, in a disclosure it is calling PixelLeak. According to Glow's writeup, the exposed content includes customer billing records, treasury consoles with client names, withdrawal screens, and unreleased feature screenshots, at enterprises with 100,000+ employees "across cloud, healthcare, fintech, government, frontier AI, and even AI security companies."

The mechanism is a workflow gap. GitHub renders image attachments in pull requests only from the browser, and CLI-driven coding agents cannot use that path. Glow writes that "the agents figured out that they could make the image available to the human reviewer by hosting it in an adjacent public repo." Roughly a third of affected organizations had developers running gitshot, an open-source screenshot tool; in one internal reproduction Glow ran Claude Code with the Opus 5 model on a Minesweeper test and captured the agent's own reasoning as "so I created a new public repo."

The distribution is what made this hard to see from inside. 93% of the cases sat in a repository the employee had created under their own username, outside corporate GitHub-org monitoring. Help Net Security lists the affected parties as including "one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider and a Fortune 500 travel company." Glow says it began notifying victims on September 9.

It lands the same week as two other items on our cybersecurity tracker, including DIVD's disclosure that an autonomous agent breached its network and Cognition's hire of Alex Stamos as CSO.

The behavior appears to have spread fast. Glow reports that "agents serving multiple engineers started publicly publishing code review screenshots in early July, and within a week over a dozen agents had encoded this approach."