#gitlost
July 8, 2026 at 9:11 AM
omg THIS IS AN ACL PROBLEM NOT AN LLM PROBLEM

STOP GIVING PUBLICLY ACCESSIBLE AGENTS UNFETTERED ACCESS TO RANDOM SHIT

noma.security/blog/gitlost...
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by pos...
noma.security
July 8, 2026 at 10:21 AM
My bot lives! @gitlost.net (formerly gitlost on Twitter) lives on BlueSky! 😀
link: make sure MachO closes the damn files Windows is a ridiculous operating system designed by toddlers, and so requires us to close all…
April 8, 2025 at 5:06 AM
GitHub AI agent leaks private repos when asked nicely
GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix - or even any documentation - for GitLost
www.theregister.com
July 8, 2026 at 7:52 PM
GitHub AI agent leaks private repos when asked nicely
GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix - or even any documentation - for GitLost
www.theregister.com
July 7, 2026 at 7:50 PM
GitHub AI agent leaks private repos when asked nicely
GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix - or even any documentation - for GitLost
www.theregister.com
July 10, 2026 at 3:53 AM
We need GitLost from X here on BlueSky!
x.com
x.com
December 5, 2024 at 12:30 PM
New Article:
New AI Security Threats: HalluSquatting, Ghost Approval, and GitLost Explained

Security Now details how these innovative attack techniques are exploiting AI agents and why developers and users must take action.
New AI Security Threats: HalluSquatting, Ghost Approval, and GitLost Explained | TWiT.TV
Security Now details how these innovative attack techniques are exploiting AI agents and why developers and users must take action.
twit.tv
July 15, 2026 at 7:35 PM
New Podcast Episode:
Security Now: HalluSquatting, GhostApproval & GitLost
Patch Tuesday Breaks Records
with Steve Gibson, @leolaporte.me
Security Now: HalluSquatting, GhostApproval & GitLost | TWiT.TV
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators
twit.tv
July 15, 2026 at 3:35 AM
we need gitlost on bluesky
@gitlost on Twitter
twitter.com
April 13, 2023 at 10:11 PM
The weird new AI security problem:

If a coding model hallucinates a repo, package, or URL…

An attacker can create it.

That is HalluSquatting.

Security Now also gets into GitLost, GhostApproval, and private code leak risks.
Security Now: HalluSquatting, GhostApproval & GitLost | TWiT.TV
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators
buff.ly
July 16, 2026 at 7:26 PM
אתם ארגון שיש לו מאגרי קוד פומביים במקביל לפרטיים? משתמשים יכולים לפתוח לכם טיקטים?
ברכותי, בגלל שהכל מטומטם ובמיוחד genAI, אתם חשופים למתקפה.

בהנתן שהתוקף יבקש יפה, כמובן.

noma.security/blog/gitlost...
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by pos...
noma.security
July 8, 2026 at 7:32 PM
winbuzzer.com/2026/07/09/g...

A look at GitLost, the GitHub Agentic Workflows prompt-injection case where public issue text, private repo access, and public comments collide.

#AI #GitLost #GitHub #GitHubActions #PromptInjection #AIAgents #AgenticAI #AISecurity #GitHubCopilot #Cybersecurity
GitLost Prompt Injection Can Leak GitHub Private Repos
A look at GitLost, the GitHub Agentic Workflows prompt-injection case where public issue text, private repo access, and public comments collide.
winbuzzer.com
July 9, 2026 at 4:56 PM
📣🚨 Researchers demonstrate #GitLost, a prompt injection vulnerability that made GitHub’s AI agent expose private repo data through a crafted public issue and guardrail failures.

Listen to this news: hackread.com/gitlost-gith...

#GitHub #GitHubActions #AI #Cybersecurity #Vulnerability
GitLost: GitHub's AI Agent Tricked Into Leaking Private Repository Data
Noma Labs details GitLost, a prompt injection flaw that made GitHub's AI agent expose private repo data through a crafted public issue and guardrail failures.
hackread.com
July 7, 2026 at 1:14 PM
When will people learn what trust boundaries are?

You cannot have the same instance of an agent accessing things in two different security boundaries.

In the worst case here you may need a completely separate instance of the agent for every private repo an org has.

noma.security/blog/gitlost...
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by pos...
noma.security
July 8, 2026 at 6:11 PM
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security #devopsish noma.security/blog/g...
July 10, 2026 at 9:30 PM
GitLost showed a GitHub AI agent could be steered from a public issue into exposing private repo data. The bigger problem is the trust boundary, not just the prompt. #GitHub #CyberSecurity #AI
GitLost Showed GitHub Agentic Workflows Could Leak Private Repositories From a Public Issue
GitLost showed that GitHub Agentic Workflows could be steered from a public GitHub issue into reading a private repository and posting its contents publicly. The affected feature is GitHub Agentic Workflows, a Copilot feature in public preview, and the disclosed proof of concept depended on the same agent having access to untrusted public issue text and readable private repositories in one organization.
novaknown.com
July 12, 2026 at 8:04 PM
"After a GitHub automation assigned the issue, an event-triggered workflow caused the agent to fetch the contents of README.md from both the poc (public) and testlocal (private) repositories. The agent then posted the contents as a public comment on the issue in the public repo."

lol, lmao
GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix – or even any documentation – for GitLost
www.theregister.com
July 8, 2026 at 1:03 PM
GitHub AI agent leaks private repos when asked nicely 🤦‍♂️ www.theregister.com/security/202...
GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix – or even any documentation – for GitLost
www.theregister.com
July 8, 2026 at 4:29 PM
github's new agentic workflows will hand over your private repos if a stranger just opens a public issue

the one word that slipped it past the guardrails: 'additionally' https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
noma.security
July 8, 2026 at 10:26 AM
Want to access private GitHub repos?

Just ask the GitHub AI Agent... but nicely 😇

www.theregister.com/security/202...
GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix - or even any documentation - for GitLost
www.theregister.com
July 8, 2026 at 4:43 AM