
Besides showing pictures of internal and pre-release software, the leaked screenshots reportedly include corporate and client information, financial data, and even screen recordings for a money-movement interface. The report, called PixelLeak, comes from endpoint security firm Glow, and it details how the leaks happened. The root cause is surprisingly simple and likely to induce a forehead slap.
It's become customary in development work related to UI and UX (and other categories) to include screenshots showing previews or before/after comparisons of tweaked features, for review purposes. Said images travel as attachments to the respective code changes, also known as "pull requests" (PRs) in dev parlance.
When using GitHub (and potentially other code repository services), humans see a graphical interface for easily attaching an image to a PR. Meanwhile, bots are limited to using the command-line interface, which currently does not have that feature available for private repositories.
As the efficient and smart agents they are, the clankers came up with a simple solution: publish the PR as usual to the private repository, and include an image placeholder linking to a file that's hosted in a public repository instead. There, problem fixed! The user is happy and likely has no idea what happened unless they notice the problem somehow and start asking the bot some hard questions.
New hack exploits AI hallucinations to trick agents into running malicious code
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://www.tomshardware.com/tech-industry/cyber-security/SPONSORED_LINK_URL
- https://www.tomshardware.com/tech-industry/cyber-security/ai-agents-inadvertently-leak-13-000-internal-screenshots-from-organizations-list-of-companies-includes-fortune-500-and-a-frontier-ai-lab#main
- https://www.tomshardware.com/membership
- Amazon and Synopsys ink multi-year billion-dollar deal in multi-year IP agreement to accelerate AI chip design efforts
- Buying used CPUs can expose users to existing bans from anti-cheat engines, and there's no way to check for violations before purchase
- OpenAI says actors linked to China-based Moonshot AI spearheaded a campaign to extract its models’ hidden reasoning
- Google freezes open-source bug bounty program amid flood of invalid AI slop submissions
- OpenAI says actors linked to China-based Moonshot AI spearheaded a campaign to extract its models’ hidden reasoning
Informational only. No financial advice. Do your own research.