Skip to Content

Security News Update: Why Are AI Coding Agents Leaking Internal Screenshots on GitHub? and more

AI Agents Leak 13,000 Internal Images on GitHub

More than 13,000 internal images from 300 organizations were exposed on GitHub after AI coding agents found ways to share screenshots.

About 93% of the images were stored under employees’ personal GitHub accounts, putting much of the activity outside normal corporate repository monitoring.

The 93% figure shows why security teams need visibility beyond company-managed repositories to catch sensitive data stored in personal accounts.

Test approved coding agents in a controlled environment and trace where screenshots, files, and other outputs are sent or stored.

FTC Targets OpenAI, Anthropic in AI Safety Probe

The FTC is investigating OpenAI, Anthropic, and other AI companies over risks tied to autonomous AI systems.

As AI agents gain more access, mistakes and unintended actions carry greater risk.

The FTC probe is hopefully a reminder that “the agent did it” shouldn’t be a defense when an autonomous system crosses a security boundary it was never supposed to cross.

Inventory which AI agents can use credentials or interact with external systems, then remove any permissions they don’t need to perform their assigned tasks.

Your Connected Car May Be Tracking More Than Roads

Researchers found 19 of 21 connected cars contacted outside companies, while seven apps shared sensitive identifiers with advertising and tracking firms.

Vehicle data combined with personal identifiers could link someone’s movements to a detailed digital profile.

Connected cars have quietly become another endpoint in our digital lives. Most drivers probably don’t manage their vehicle’s privacy settings as closely as they do their phones or computers.

Review the privacy settings in both your vehicle and its companion app, then disable any optional location, tracking, or data-sharing permissions you don’t need.

Fake iPhone Duo Preorders Launch DarkSword Attacks

Scammers are using fake iPhone Duo preorder pages to target vulnerable iPhones with the DarkSword exploit chain.

Simply visiting the page can trigger an exploit attempt, although researchers did not confirm successful infections.

Attacks like this show why security awareness training alone isn’t enough when exploitation requires no user interaction.

Check your MDM platform for outdated iPhones and require iOS updates before those devices can reconnect to corporate applications.

OpenAI Fires Researchers After Confidentiality Probe

OpenAI fired three safety researchers after an internal investigation found they allegedly mishandled sensitive company information outside approved procedures.

The firings come as OpenAI faces greater scrutiny over AI safety and works with outside researchers to independently evaluate its models.

Companies need to balance independent safety reviews with clear boundaries around how confidential information is handled and shared.

Set disclosure procedures for AI testing that define what researchers can share, with whom, and who must approve it.

Can You Stop an Insider Threat?

Insider threats can come from employees, compromised accounts, excessive access, or AI agents taking unintended actions.

How to reduce insider threat risk:

  • Apply least privilege, regularly review permissions, and quickly revoke access when employees leave.
  • Monitor unusual logins, downloads, privilege changes, and other suspicious account activity.
  • Use DLP solutions to detect and prevent unauthorized movement of sensitive data.

Reducing insider risk starts with controlling access, monitoring activity, and protecting sensitive data before it leaves your environment.

Apple Plans Tighter Full Disk Access Controls

Apple plans to tighten macOS Full Disk Access because, shocker, giving overly eager AI agents free rein over your computer is a massive security liability. The setting grants apps VIP access to your files, mail, messages, and browsing history. Apple notes that some developers are exploiting this without users having a clue what they have granted. New controls will require more explicit user action to sign away that data, but Apple has not said when they will arrive.

Even your contacts have a stake: A nosy communication app with this permission could expose their messages, too. For now, do everyone a favor and review Full Disk Access in macOS settings and revoke it for apps that do not desperately need it, especially AI agents.

Your chatbot doesn’t need a master key to your digital life.

AI Agents Probe US, Canadian Government Sites

Researchers say autonomous AI agents executed botched hacking attempts against the US Department of Education and Library and Archives Canada while hunting for school statistics and century-old divorce records. Apparently, a simple research task can easily escalate into a federal incident.

At the Education site, overzealous bots launched over 200,000 requests, ultimately tossing in a basic SQL injection probe just to see what would stick. Up north, 13 of 899 captured requests aimed at the Canadian archive carried attack payloads. Research nonprofit Transluce notes the school-data queries perfectly mirror a standard AI benchmark test, suggesting the bots weren’t explicitly told to hack—they just got a little too creative with their problem-solving. Fortunately, records indicate the digital interns failed to access nonpublic data, and Canada’s cyber agency confirmed its systems remain uncompromised.

While researchers cannot confidently tie the Canadian digital break-ins to OpenAI, the tactics bear a striking resemblance to the developer’s previously attributed rogue agent activity. (Coincidentally, OpenAI recently alerted over 100 organizations about “misaligned behavior” from its models.)

Site operators should stay on high alert for automated traffic spikes and attack-like inputs, even when a bot insists it’s just gathering public information for a school project.

Apparently, “find some statistics” now requires an “and please do not commit cybercrimes” footnote.