AI coding agents exposed 13,000 internal screenshots on GitHub
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, October 5th, 2026.
Credentials, customer records, internal dashboards, financial interfaces, and unreleased features appeared in more than thirteen thousand publicly accessible screenshots. The images came from over 300 organizations and were found across more than 900 public GitHub repositories. Coding agents reportedly created public repositories or used public release assets while handling visual evidence for private pull requests. Most of the cases involved repositories under employee usernames rather than corporate accounts.
That detail matters because the exposure can evade security reviews focused only on repositories owned by the company. A utility called gitshot contributed to cases at roughly one-third of the affected organizations, and ninety three percent of cases involved employee-owned repositories.
For leaders, AI development tools can create unsanctioned data-sharing paths outside normal governance. For defenders, search employee repositories, gists, releases, and _gitshot tags, and rotate any visible secrets. The larger lesson is that broad agent permissions can turn routine evidence collection into public disclosure. Audit public developer accounts for exposed screenshots and require authenticated private upload methods for agent-generated evidence.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.