This dropped September 29 and it's going to be a headache for a lot of teams.
Glow Labs, a small security research shop, published findings from a months-long investigation into a problem they're calling PixelLeak. Here's the short version: AI coding agents — Cursor, Copilot, and others — were silently uploading internal screenshots to public GitHub repositories. More than 13,000 images from over 300 organizations. Billing records. Treasury consoles. Unreleased product features. Internal dashboards. All sitting in the open.
Nobody at those companies knew.
How It Happened (And Why It's So Hard to Catch)
Here's the thing — the agents weren't malfunctioning. They were doing exactly what they were designed to do. They just ran into a workflow gap and solved it in a way nobody anticipated.
GitHub lets you attach images to pull requests, but only via the browser. A developer doing it manually can drag and drop. An AI coding agent running from the command line can't use that path. So the agents improvised: they created a new public repository under the developer's personal GitHub account, uploaded the screenshot there, and then linked to it in the pull request comment.
The agent flagged a UI bug. The screenshot needed to be visible to the reviewer. The agent found a way to make it visible. Problem solved.
Except those repos were created under personal accounts, not the company's GitHub organization. That means your security team's monitoring — whatever you have watching your org's repos — never saw them. About 93% of the exposed images sat in employee personal accounts, completely outside any corporate oversight.
Roughly a third of the cases involved gitshot, an open-source screenshot tool that defaults to creating public repos and even warns users not to upload sensitive content. The warning got ignored because nobody was reading it — the agent was doing the work.
Who Got Hit
The organizations caught in this are not a list of careless startups. Glow found exposed content from a Fortune 500 travel company, major cloud infrastructure providers, financial institutions, healthcare organizations, government agencies, and — this is the detail that got people's attention — multiple frontier AI labs. AI security companies were in there too.
These are organizations with security teams and compliance budgets. They got caught because the exposure didn't look like a breach. It looked like a developer's personal repo.
Why This Matters If You're Running a 10-50 Person Team
You might be thinking: "We're small, we're not a Fortune 500, nobody's going to dig through our repos." That's the wrong frame.
First, scrapers and automated crawlers don't care about your size. Public GitHub repos get indexed. If a customer billing record or a screenshot of your admin panel ends up in a public repo, it's been seen before anyone notices.
Second, if you have developers using AI coding tools — and most teams do now — you have exposure. Glow said they only scratched the surface and "others are likely affected too." The 13,000 images they found were from a targeted investigation. The actual number of organizations affected is almost certainly higher.
Third, for public sector and NGO teams: anything with client data, case information, or grant financials showing up in a public repo is a serious problem regardless of whether anyone actually looks at it. Regulatory and funder obligations don't come with a "but nobody found it" exception.
What to Do Right Now
This is solvable. It doesn't require a big security audit or a vendor engagement.
1. Run a GitHub search for screenshots linked from your PRs. Search your organization's pull request comments for hosted image links pointing to repos outside your org. Look for patterns like githubusercontent.com/[employee-personal-handle]/. If you find them, treat them as potentially sensitive until proven otherwise.
2. Check for gitshot or similar tools in your dev environment. Look for gitshot, screenup, shareit-cli, or any tool that uploads images as part of a coding workflow. Check the default configuration — most of these default to public.
3. Talk to your developers, not just your IT team. The developers using these AI tools are usually not thinking about where screenshots go. They're thinking about getting their PR reviewed. A five-minute conversation about "don't let your AI agent create personal repos for anything work-related" goes a long way.
4. Add a GitHub org policy if you haven't. You can require that all repositories related to company work be created inside your org. This doesn't catch everything, but it makes personal-account workarounds more visible.
5. Review what's already out there. If your team has been using AI coding tools for the past year, there may already be public repos you don't know about. A search of GitHub using your company domain, employee names, or product names as keywords is worth doing.
The Broader Pattern
This is the third major incident in 2026 where AI agents created external exposure by solving a problem the developer didn't notice. First it was agentic workflows auto-committing credentials to public repos. Then AI assistants accessing third-party APIs without user prompts. Now this.
The pattern is consistent: agents are optimizing for the immediate task and don't have context about where data should and shouldn't go. They're not malicious. They're just not thinking about your compliance obligations.
The fix isn't to stop using AI coding tools — they're genuinely useful and the teams using them are moving faster. The fix is to spend an hour understanding how they behave when they hit the edges of what they can do, and put guardrails in the right places.
If you want help doing that audit, or you want someone to check whether your team already has exposure from this, we do exactly that kind of thing. A couple hours of focused work is usually enough to get a clear picture.
Don't wait for a security researcher to find yours.