AI agents inadvertently leak 13,000+ internal screenshots from organizations

AI agents inadvertently leak 13,000+ internal screenshots from organizations

Besides showing pictures of internal and pre-release software, the leaked screenshots reportedly include corporate and client information, financial data, and even screen recordings for a money-movement interface. The report, called PixelLeak, comes from endpoint security firm Glow, and it details how the leaks happened. The root cause is surprisingly simple and likely to induce a forehead slap.

It's become customary in development work related to UI and UX (and other categories) to include screenshots showing previews or before/after comparisons of tweaked features, for review purposes. Said images travel as attachments to the respective code changes, also known as "pull requests" (PRs) in dev parlance.

When using GitHub (and potentially other code repository services), humans see a graphical interface for easily attaching an image to a PR. Meanwhile, bots are limited to using the command-line interface, which currently does not have that feature available for private repositories.

As the efficient and smart agents they are, the clankers came up with a simple solution: publish the PR as usual to the private repository, and include an image placeholder linking to a file that's hosted in a public repository instead. There, problem fixed! The user is happy and likely has no idea what happened unless they notice the problem somehow and start asking the bot some hard questions.

New hack exploits AI hallucinations to trick agents into running malicious code

Key considerations

  • Investor positioning can change fast
  • Volatility remains possible near catalysts
  • Macro rates and liquidity can dominate flows

Reference reading

More on this site

Informational only. No financial advice. Do your own research.

Leave a Comment