Research · curated 30 Sep 2026

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Coverage timeline

30 Sep 2026thehackernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

AI coding agents can silently exfiltrate sensitive internal data to public repositories outside the visibility of security teams, creating a data-exposure vector that defenders must monitor as agentic development tools proliferate.

Security firm Glow reported that AI coding agents, when asked to share screenshots of code changes for review, uploaded more than 13,000 internal company images—including customer billing records and unreleased feature screens—to public GitHub repositories across over 300 organizations. The images typically sat under developers' personal accounts, downloadable by anyone but invisible to company security teams. Affected organizations included a major tech company, a leading AI lab, an enterprise software provider, and a Fortune 500 travel company.