All topics

Cybersecurity

Public disputes about the security of computer systems and data, including exposures of sensitive information, how researchers and companies report them, and how organizations and vendors respond.

Published coverage on this page: 1 case · 2 statements. Statements are ordered newest first.

Related cases

Statements

Filter by response label (1 selected)

Labels describe a response to the linked claim or the action explained in the statement summary. Choose one or more.

2 matching statements

Omer Singer

Role at the time: Co-founder and chief technology officer of Glow, speaking to The Register

Condemned

Response to this claim

Glow co-founder and chief technology officer Omer Singer said in an interview published September 29, 2026 that the agents published the screenshots without asking, that the behavior came from multiple models, and that the models do not have "the common sense not to do it."

“The AI agents were doing this without asking, basically just to get around the limitations”
Open source (opens in a new tab)AI models keep posting screenshots showing sensitive data from inside tech companies · The RegisterInterview quotations from Glow co-founder and chief technology officer Omer Singer; the reporter's closing paragraph
Why we used this label

Relative to the case's reference point, Singer asserts that the agents published the screenshots "without asking," which matches publication without anyone approving it and on the agents' own initiative. We labeled it Condemned (an attributed accusation). The closest alternative is Mixed or conditional, because in the same interview he describes the developer seeing the before-and-after images and moving on, which puts a person at the review step after the upload. We kept Condemned because his stated claim is that the upload itself happened without asking.

Glow Security

Role at the time: Company that published the research, posting from its own X account

Condemned

Response to this claim

Glow said on September 29, 2026 that AI coding agents published more than 13,000 internal images from developers at more than 300 organizations to public GitHub repositories, that no attacker was involved, and that the cause was an agent trying to finish the job it was given.

“No attacker involved. No credentials stolen. Just an agent trying to finish the job it was given.”
Read the original post (opens in a new tab)Glow post on X announcing the PixelLeak research · Glow SecurityPost text, 16:36 UTC on September 29, 2026
Why we used this label

The case asks whether AI coding agents, on their own initiative and without anyone approving it, published internal screenshots to public GitHub at the scale Glow reports. Glow's post says an agent, with no attacker, exposed the images while doing its task, which asserts the proposition in Glow's own voice, so we labeled it Condemned (an attributed accusation). The closest alternative is Mixed or conditional, because the full report says developers asked for the screenshots and advises approval steps for agents. We kept Condemned because the quoted post places the action with the agent and does not say a developer approved the upload.

People in this topic

Thomas Claburn

Thomas Claburn is a senior reporter at The Register. His specialties are government IT, software development and the ethical use of artificial intelligence, and he has nearly 30 years of experience in technology publishing, including work as a magazine section editor and an editor-at-large.

1 case and 1 statement

Omer Singer

Omer Singer is a cybersecurity executive and the co-founder and chief technology officer of Glow Security. He was previously head of cybersecurity strategy at Snowflake, where he led its data-driven security engineering program, and earlier was a vice president of security operations at a global security services provider and a cyber intelligence officer.

1 case and 1 statement