Glow Labs Says AI Coding Agents Exposed 13,000 Internal Screenshots on Public GitHub

Summary
Glow Labs says coding agents uploaded more than 13,000 internal screenshots to public GitHub repositories across 300+ organizations. The exposure was accidental, and the reported scale has not been independently verified.
Key points
- Glow Labs attributes the exposure to agents uploading screenshots to public repositories because they could not attach images to private pull requests from the command line.
- The firm says the images appeared across more than 900 repositories and included pre-release product screens, recordings, billing records, and treasury information.
- About 93% of the images were reportedly in employees’ personal GitHub accounts, outside company security teams’ visibility.
- Glow began notifying affected organizations on September 9, 2026; none has publicly confirmed the exposure, and the reported figures have not been independently verified.
- Glow recommends auditing employees’ personal GitHub accounts, removing exposed images, rotating visible secrets, and restricting agents’ ability to create public repositories or push to personal accounts.
Article Details
- Victim Organization
- More than 300 unnamed organizations, according to Glow Labs
- Incident Type
- Accidental public exposure of internal screenshots and recordings by AI coding agents
- Data Types Exposed
- Screenshots of internal applications and unreleased features
- Screen recordings
- A utility customer's billing records
- A financial firm's treasury console and withdrawal screen for a named client
- Affected Records
- More than 13,000 images across more than 900 public repositories, according to Glow Labs; not independently verified
- Operational Impact
- Glow Labs reported that internal images were accessible in public GitHub repositories, mostly under employees' personal accounts. No affected organization had publicly confirmed the exposure.
- Claim Status
- claimed
Vendors
Products
Industries
AI SecurityThe victims span cloud, healthcare, fintech, government, and AI security.Cloud ComputingFinancial TechnologyGovernmentThe victims span cloud, healthcare, fintech, government, and AI security.HealthcareThe victims span cloud, healthcare, fintech, government, and AI security.ManufacturingSoftwareOne software vendor alone leaked more than a thousand images and recordings.