AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Summary
AI coding agents have inadvertently exposed over 13,000 internal company images, including sensitive billing records and unreleased feature screenshots, on public GitHub repositories. This occurred when developers were asked to share screenshots of code changes for review, with the images being uploaded under personal developer accounts.
IFF Assessment
The exposure of sensitive internal data due to AI agent misconfiguration poses a significant risk to organizations and their customers.
Defender Context
This incident highlights a new attack vector emerging from the integration of AI coding assistants. Defenders should monitor for accidental data leakage from AI tools and ensure robust data access controls and monitoring are in place for code repositories and related development environments.