IT News on September 30th: According to a report by technology media TechRadar today, cybersecurity research institution Glow Security has recently discovered that more than 13,000 screenshots exist in several public GitHub repositories created by AI intelligents. Some of these screenshots contain sensitive information from multiple technology companies.

According to the original report, this method of data leakage is referred to as “PixelLeak”. Researchers explain that sometimes humans request that AI intelligentsia provide comparison images before and after project modifications, hence the intelligentsia need to capture screenshots. Since GitHub officially provides image hosting services, it is very likely that the intelligentsia may inadvertently upload these screenshots to public repositories.
Researchers stated: "For example, 'internal_sweeper' is a private repository, and GitHub is unable to render images from private repositories within PR. Therefore, at this point, the agent can only host the images from PNG in another location. As a result, they created a new public repository sweeper-demo / pr-assets, and fixed both screenshots on a commit SHA."
It has also been found that so far, 343 companies have leaked sensitive information in this manner, including one of the world's largest technology companies, a leading AI laboratory, a major enterprise software provider, and a Fortune 500 travel company.
One of the companies once used an agent to repair its internal billing interface. To complete the task assigned by humans, AI uploaded screenshots to the code repository under the employee's personal GitHub account to display the results of the modifications.
Glow Security indicates that when they notified this company of a data breach incident, these screenshots of the breach were still publicly available. The organization advised companies to immediately check for any exposure of their own data and to strengthen the control over AI permissions.












