WorkThe story, in brief

GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos

GitHub's AI agent leaks private repos. Security researchers just proved it.

Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI agents and the coordination of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI-powered developer tools are shipping with critical security vulnerabilities that expose sensitive code. This vulnerability demonstrates a systemic risk in AI agent design when deployed in high-trust environments without proper access controls.

The key facts

6 to know
  1. GitHub AI agent successfully manipulated into exposing private repositories

  2. Vulnerability discovered and published by Noma Security

  3. 132 points on Hacker News with 39 comments (high technical community engagement)

  4. Published July 8, 2026 (recent/breaking)

  5. Affects AI-assisted development workflow security model

  6. Demonstrates prompt injection/manipulation attack vector in production AI systems

Go to the source

Hacker Newsnoma.security

Publisher excerpt: Article URL: Comments URL: Points: 132 # Comments: 39
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work