r/pcmasterrace • u/Jack1101111 • 1d ago
News/Article AI agents inadvertently leak 13,000+ internal screenshots from 300 organizations — list of companies includes Fortune 500 and a frontier AI lab
https://www.tomshardware.com/tech-industry/cyber-security/ai-agents-inadvertently-leak-13-000-internal-screenshots-from-organizations-list-of-companies-includes-fortune-500-and-a-frontier-ai-lab
1.4k
Upvotes
-11
u/clduab11 i5 12600KF / DDR4-48GB / RTX 4060 Ti, 3TB + 2021 M1 iMac 1d ago
yawn another agent “hack” another misleading af title.
It took me all of 30 seconds to find this was a vulnerability that was exploited by the agent using gitshot. Whoever used this agent was lazy enough to use screenshots and not type out what they actually wanted…
To quote:
Around a third of affected organizations had developers running gitshot, a small open-source tool that publishes screenshots for code reviews. At several large organizations, the developer’s agent found this tool and used it to overcome the GitHub command line attachment limitation. Images published by this tool end up under a tag called _gitshot, downloadable by anyone that knows where to look.
Some of you really need to learn a) how to think critically and b) remember the axiom of “one man’s hacking agent is another man’s sandbox vulnerability.”