skip to content
The Weighted Average

Wire

PixelLeak finds 13,000 AI-posted screenshots

Glow Security’s PixelLeak investigation found more than 13,000 screenshots tied to 343 organizations in public GitHub repositories, including credentials, personal information, and unreleased product work, according to The Register’s report. The incidents involved multiple AI agents performing legitimate development work rather than a named attacker, which makes the failure a permissions and destination-control problem, not only a prompt-injection problem. Teams deploying coding agents should extend the archive’s approval test for consequential actions to outbound files and public-hosting destinations; inspect side effects, not just generated code.