Researchers at Noma Security disclosed on or around July 7, 2026, a technique called "GitLost" that abuses GitHub's "Agentic Workflows" feature to make AI agents read the contents of a private repository through a public repository issue and post them in a public comment. An attacker needs no organizational access, no credentials, and no coding skills—only the ability to file a single ordinary issue on a public repository. According to the report, when an AI agent processes that issue, it follows the hidden instructions embedded within it, reads files such as the README of a private repository, and posts them as a public comment.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.