GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos (noma.security)
from cm0002@libretechni.ca to cybersecurity@infosec.pub on 08 Jul 17:44
https://libretechni.ca/post/1800267

#cybersecurity

threaded - newest

JRaccoon@discuss.tchncs.de on 08 Jul 21:55 collapse

I think the whole thing is a bit clickbaity. The only reason it works is that they specifically configured the AI workflow to have access to both the public and the private repositories. The solution? Don’t do that. The only thing GitHub could fix here is disallowing such an obviously unsafe configuration.