
Besides showing pictures of internal and pre-release software, the leaked screenshots reportedly include corporate and client information, financial data, and even screen recordings for a money-movement interface. The report, called PixelLeak, comes from endpoint security firm Glow, and it details how the leaks happened. The root cause is surprisingly simple and likely to induce a forehead slap.
It's become customary in development work related to UI and UX (and other categories) to include screenshots showing previews or before/after comparisons of tweaked features, for review purposes. Said images travel as attachments to the respective code changes, also known as "pull requests" (PRs) in dev parlance.
When using GitHub (and potentially other code repository services), humans see a graphical interface for easily attaching an image to a PR. Meanwhile, bots are limited to using the command-line interface, which currently does not have that feature available for private repositories.
As the efficient and smart agents they are, the clankers came up with a simple solution: publish the PR as usual to the private repository, and include an image placeholder linking to a file that's hosted in a public repository instead. There, problem fixed! The user is happy and likely has no idea what happened unless they notice the problem somehow and start asking the bot some hard questions.
New hack exploits AI hallucinations to trick agents into running malicious code
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://www.tomshardware.com/tech-industry/cyber-security/SPONSORED_LINK_URL
- https://www.tomshardware.com/tech-industry/cyber-security/ai-agents-inadvertently-leak-13-000-internal-screenshots-from-organizations-list-of-companies-includes-fortune-500-and-a-frontier-ai-lab#main
- https://www.tomshardware.com/membership
- California tech CEO arrested, faces up to 20 years in prison for smuggling $300 million in Nvidia AI servers to China
- NVIDIA Launches DSX Ready to Qualify Power and Cooling Products for AI Factories
- Amazon and Synopsys ink multi-year billion-dollar deal in multi-year IP agreement to accelerate AI chip design efforts
- Amazon and Synopsys ink multi-year billion-dollar deal in multi-year IP agreement to accelerate AI chip design efforts
- OpenAI says actors linked to China-based Moonshot AI spearheaded a campaign to extract its models’ hidden reasoning
Informational only. No financial advice. Do your own research.