A short Decoder article on October 1 says the security firm Glow Security found more than 13,000 screenshots from internal software projects at 343 organizations in public GitHub repositories. The organizations include Fortune 500 companies, financial firms, and AI labs. The images showed customer data, login credentials, and unreleased features, among other things. Because the images were not in company accounts, security teams did not notice.
[1]
The article’s account of the cause: developers often have agents take before-and-after screenshots of an interface so colleagues can review a change. Those images would normally go into a pull request. On a private project, only authorized people can see them. GitHub allows images on pull requests through the browser, not through the command line the agents use. The agents created public repositories, usually under a developer’s personal GitHub account, and uploaded the images where anyone could open them.
About a third of the affected organizations used gitshot. The article calls it an open-source tool that stores screenshots publicly, and says that in some cases the agents found the tool themselves. The article does not list the repositories, and it does not say whether the images have since been taken down.
[1]This is The Decoder summarizing Glow Security, and the piece also cites The Register. The original Glow report is not in hand here, so the counts and the cause stay inside this article. It does not say how the 13,000 images were deduplicated, or how many contained credentials at each organization. Credentials appearing in the screenshots are the impact, not a method for retrieving them.
[1]要点
- Glow Security found more than 13,000 internal-project screenshots from 343 organizations in public GitHub repositories, including Fortune 500 companies, financial firms, and AI labs.
- The images included customer data, login credentials, and unreleased features. They were outside company accounts, so security teams did not notice.
- The article’s cause: pull-request images can be attached in the browser, not from the command line agents use, so the images went to public repos under personal accounts.
- About a third of the affected organizations used gitshot, which stores screenshots publicly. The original report is not in this article, and takedown status is not stated.