Данные о числе изображений и организаций The New Stack приводит со слов команды исследователей безопасности Glow Labs.
В разборе утечки PixelLeak Glow Labs, команда исследователей безопасности, описала, как ИИ-помощники разработчиков выкладывали внутренние скриншоты в открытые репозитории GitHub, чтобы показать результат правок. По данным команды, разработчики из более чем 300 организаций опубликовали более 13 000 внутренних изображений.
В исследованных случаях ИИ-помощники не могли через командную строку прикрепить скриншоты для проверки. Помощники обходили ограничение, размещая изображения в отдельном открытом репозитории.
Glow Labs рекомендует проверять личные аккаунты сотрудников на GitHub: в 93% найденных случаев изображения лежали в репозиториях, созданных сотрудниками под своим именем. Исследователи советуют проверять также аккаунты бывших сотрудников и изображения во вложениях к релизам.
Проверка утверждений:
- Glow Labs сообщила, что ИИ-помощники разработчиков публиковали внутренние скриншоты в открытых репозиториях GitHub, чтобы показать результат правок. (подтверждено первоисточником: доказательство; «Each case investigated during our “PixelLeak” research started with a developer asking an agent to prove that a visual change worked. The software was changed, for example with a fix to the user interface layout, and the reviewers needed to see the before and after. That’s where the agents ran into a wall. GitHub has an official image hosting service built directly into the site’s pull request interface. This service supports human developers using a web browser, but coding agents use a text-based CLI. As a result, the agents found that they could not include before/after screenshots for human review. How did they work around this limitation? The agents figured out that they could make the image available to the human reviewer by hosting it in an adjacent public repo. They just didn’t consider the security implications.»)
- По данным Glow Labs, разработчики из более чем 300 организаций опубликовали более 13 000 внутренних изображений. (подтверждено только публикацией-переносчиком: доказательство; «AI coding agents trying to work around a limitation in GitHub’s command-line tool ended up publishing more than 13,000 internal images to public repositories, according to an incident report Glow Labs released this week. The company calls the incident PixelLeak. Developers at more than 300 organizations were affected»)
- В исследованных случаях ИИ-помощники не могли прикрепить скриншоты для проверки через командную строку и обходили ограничение, размещая изображения в отдельном открытом репозитории. (подтверждено первоисточником: доказательство; «GitHub has an official image hosting service built directly into the site’s pull request interface. This service supports human developers using a web browser, but coding agents use a text-based CLI. As a result, the agents found that they could not include before/after screenshots for human review. How did they work around this limitation? The agents figured out that they could make the image available to the human reviewer by hosting it in an adjacent public repo. They just didn’t consider the security implications.»)
- Glow Labs рекомендует проверять личные аккаунты сотрудников на GitHub: в 93% найденных случаев изображения лежали в репозиториях, созданных сотрудниками под своим именем. (подтверждено первоисточником: доказательство; «Look beyond your org: 93% of the cases had images that sat in a repository an employee created under their own username. Start instead with the people who commit to your private repositories.»)
- Glow Labs рекомендует проверять также аккаунты бывших сотрудников и изображения во вложениях к релизам. (подтверждено самой публикацией: доказательство; «Audit departed employees too: Include anyone who has left, and review their accounts. Check releases and gists, not just files: Images attached to a release leave the file listing looking empty.»)
Публикации:
Первоисточники:
оценка 78,5 из 100 · тип: инцидент