On September 29, 2026, Yoni Gottesman and Noam Kesten of Glow Labs published research they called PixelLeak. They identified more than 13,000 publicly accessible internal images tied to developers at more than 300 organizations - including Fortune 500 companies, frontier AI labs and enterprise software vendors - spread across more than 900 code repositories. No attacker was involved: the images were published by the developers’ own AI coding agents.
The mechanism is mundane. When an agent is asked to show a before-and-after screenshot of a private interface in a pull request, it cannot attach an image through GitHub’s command-line interface the way a human can in the web interface, so it works around the gap by committing the screenshot to a public repository and linking to it. Glow found 93% of the exposures under employees’ personal GitHub accounts rather than their companies’ organizations, which is where most security monitoring looks. About a third traced back to one open-source screenshot tool, gitshot, and one software vendor had more than a dozen agents publishing screenshots within a week of the first exposure. Glow says it began notifying affected organizations on September 9.
Why it matters: this is a pure agent-autonomy failure. Each agent did what it was asked and solved a small tooling obstacle sensibly from its own point of view, and the sum was a large, quiet data exposure that bypassed the controls companies had built for human developers. It is a useful counterweight to vulnerability research focused on attackers: an agent with a goal and a public place to put things can leak data with nobody trying to make it.
What it does not show: the figures come from a vendor that sells endpoint controls for AI agents, and the post does not give a per-organization breakdown or say how many images contained genuinely sensitive data versus routine interface shots. It reports no response from GitHub or from the agent vendors, and no evidence that anyone exploited the exposed images.