ainewsblitz.com

Breaking

'GitLost' Technique Leaks Private Repos via GitHub AI Workflows

  • Security
  • AI Agents
  • Software Dev & Coding

Researchers at Noma Security disclosed on or around July 7, 2026, a technique called "GitLost" that abuses GitHub's "Agentic Workflows" feature to make AI agents read the contents of a private repository through a public repository issue and post them in a public comment. An attacker needs no organizational access, no credentials, and no coding skills—only the ability to file a single ordinary issue on a public repository. According to the report, when an AI agent processes that issue, it follows the hidden instructions embedded within it, reads files such as the README of a private repository, and posts them as a public comment.

Continue reading

The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.

$20
Read this article
$29/month
Unlimited — all 8,991 articles, the full archive, and comprehension quizzes
Save 72%
$98/year
≈ $8.17/month
Unlimited, billed once a year