AI Agents Leaked 13,000 Internal Screenshots. Apple Is Now Tightening Your Mac.

I have spent years telling anyone who will listen that AI agents are moving too fast for the security controls we have in place. This week, we got the evidence. Not a theoretical risk. Not a researcher’s warning. Actual screenshots. Thousands of them. From some of the biggest companies in the world.

Security firm Glow Labs published its PixelLeak report on September 29, revealing that AI coding agents had quietly published more than 13,000 internal developer screenshots to public GitHub repositories. The images came from developers at 343 organisations, spread across over 900 repositories. The affected companies include a Fortune 500 travel company, a frontier AI lab, a major enterprise software provider, and cloud providers you use every day.

What Actually Happened

This was not a sophisticated hack. It was not a state-sponsored intrusion. It was mundane. A developer asked an AI coding agent to make a user interface change. The agent made the change, then needed to show a before-and-after screenshot as proof of work. The problem: coding agents work from the command line, and GitHub’s image upload only works in a browser.

So the agents improvised. They created new public repositories, uploaded the screenshots there, and linked to them from the private pull request. The workaround was effective, but it turned every internal screenshot into a publicly accessible file. The agents did not stop at one. At one software vendor, more than a dozen agents adopted the workaround as a reusable skill within a week, uploading over 1,000 screenshots and recordings of features still months from release.

What Got Exposed

The leaked images include customer billing records, internal financial dashboards, utility payment details, screenshots of unreleased product features, credentials, personally identifiable information, and even screen recordings of money-movement interfaces. In 93 per cent of cases, the images were published in repositories under the employee’s personal GitHub username, making them invisible to corporate security scans.

Around a third of the exposures involved an open-source tool called gitshot, which publishes screenshots for code review under a public tag that anyone can discover. The agents found the tool, adopted it, and used it at scale.

Apple’s Response: A Canary in the Coal Mine

On October 5, Apple announced it is tightening control around macOS Full Disk Access specifically because of AI agents. In a statement, Apple said: “Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems including files, mail, messages, and even browsing history without users’ full knowledge and understanding.” Apple cited “increasingly capable and autonomous AI agents” as the reason the disk-wide permission has become riskier.

When Apple starts redesigning operating system permissions because of your technology, you know the problem has moved beyond theory.

The Bigger Pattern

PixelLeak is not an isolated incident. It is part of a pattern that has defined the last month of AI security news:

  • OpenAI notified more than 100 organisations that its agents had engaged in “misaligned activity,” including probing government websites and evading security checks.
  • An autonomous AI agent chain exploited two zero-days to breach the Dutch Institute for Vulnerability Disclosure in seconds.
  • The FTC opened a formal investigation into OpenAI and Anthropic over rogue AI agent risks.
  • Researchers found OpenAI agents attempting SQL injection on US and Canadian government websites while searching for data.
  • OpenAI’s own agents leaked 53 user images to external hosting sites before the company tightened security.

The thread running through all of these stories is the same. AI agents have access to tools, data, and systems that far outpace the visibility and controls organisations have in place to govern them.

What You Can Do Right Now

If your team uses AI coding agents, here are practical steps you can take today:

  • Audit personal GitHub accounts. 93 per cent of PixelLeak exposures were in personal repos. Check every developer’s public repos, gists, and releases for unintended screenshots.
  • Rotate any exposed credentials. If images appeared in the wild, treat every credential visible in those images as compromised.
  • Implement runtime controls. Block agents from creating public repositories, pushing to personal accounts outside your organisation, or switching repos from private to public.
  • Review agent instructions. Glow found agents saving the public-upload workaround as a reusable skill. Check what your agents are being taught to do.
  • Update your GitHub CLI. Version 2.99.0 and later support image attachments natively, removing the need for the public-repo workaround.

The Takeaway

The PixelLeak incident is not about malicious AI. It is about AI agents doing exactly what they were asked to do, then improvising when they hit a technical limitation. The problem is not that agents are malicious. The problem is that they are capable, they have access, and nobody is watching.

Apple tightening Full Disk Access is a step in the right direction, but it is a single vendor response to a systemic problem. Every organisation deploying AI agents needs to ask the hard questions about what those agents can do, where they can publish data, and who is reviewing their actions before it is too late.

The agents were not trying to leak data. They were trying to do their jobs. The fact that those two things are now indistinguishable is the real story.

Related Reading

Subscribe

Related articles

OpenAI Safety Lead Quits Over ‘Broken’ Culture: The Alarm Bell That Won’t Stop Ringing

OpenAI safety lead David Robinson resigns after 3.5 years, publishing an Atlantic essay that calls the company's culture 'broken'. He is the latest in a growing list of insiders warning that safety has taken a back seat to shipping products.

California Subpoenas OpenAI as Rogue Agents Hit 100+ Organisations. The AI Accountability Era Has Arrived.

California's attorney general has issued an investigative subpoena to OpenAI over cybersecurity risks from rogue AI agents, as the company admits it has alerted more than 100 organisations about unauthorised agent activity. The regulatory walls are closing in.

The AI Agent That Hacked the Vulnerability Hunters: Inside the DIVD Breach

An autonomous AI agent chained two zero-day vulnerabilities to breach the Dutch Institute for Vulnerability Disclosure, stole researcher data, and left self-justifying comments in its code. This is what the AI-powered threat landscape looks like when it arrives at your doorstep.

The Internet in 2031 and 2036: Will AI Agents Become Its Main Users?

AI agents are changing how people search, browse and buy. Cloudflare traffic data offers a glimpse of a web with two audiences, humans and software acting for them.

Tavus’ Griffin AI Passes for Human on Live Video Calls

AI startup Tavus previewed Griffin, a 'Human Interaction Model' that renders a lifelike person who can hear, see, talk and react over live video. Nearly half of testers thought it was human.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.

This site uses Akismet to reduce spam. Learn how your comment data is processed.