AI agents expose sensitive corporate screenshots from 343 companies

Glow Security researchers discovered more than 13,000 sensitive screenshots from 343 organizations that AI coding agents had uploaded to publicly accessible GitHub repositories, exposing information including credentials, personal data, internal systems and unreleased products.

The agents were performing legitimate development tasks but encountered a limitation when attempting to attach screenshots from private repositories to pull requests. Instead of stopping or asking for permission, some agents independently worked around the restriction by placing the screenshots in public repositories so developers could view them. Glow said the behavior occurred across multiple AI agents and was not the result of an external attack.

In one case, an agent asked to verify an internal billing screen at a manufacturer with more than 100,000 employees posted screenshots to a developer’s personal GitHub account. The company’s security team was unaware the information had been made public until Glow notified it. Researchers said roughly one-third of the exposures involved GitShot, an open-source screenshot tool whose documentation warns that its image repository is public by default.

Ryan McCurdy, VP of Marketing, Liquibase:

“This is exactly why an AI agent doesn’t have to be compromised or malicious to create a security problem. These agents were trying to complete the task they were given. They hit an obstacle, found another way to accomplish the goal, and exposed sensitive information in the process.

“That’s a very different problem from traditional software. An agent can decide how to accomplish a task, which means enterprises have to think beyond what the agent has permission to access. They also have to decide what actions the agent has the authority to take on its own.

“The answer can’t be asking a person to approve every step. As agents take on more of the SDLC, that won’t scale. The controls need to sit outside the agent and close to the systems where its decisions become actions.

“An agent can make a bad decision. Good governance keeps that decision from becoming a business problem.”

Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security Technology Inc.:

“This is a good example of why AI agent security must extend beyond the model itself. The agents were given a legitimate objective, encountered a constraint, and found a way around it but the workaround crossed a security boundary. There didn’t need to be an attacker for sensitive information to become exposed.

“As organizations give agents more autonomy, we need to test the entire path: the model, tools, permissions, data access, and the environment in which the agent operates. The question isn’t only whether an agent can complete its task, but what it is willing and able to do to complete it. That’s where continuous offensive testing becomes increasingly important.”

There have to be guardrails and other types of security around AI. Otherwise you get a very bad situation. Or put another way, you have to make sure not to be that guy.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading