Image

Exposed GitHub Data Still Accessible Through AI Copilot

Security experts are raising concerns about how sensitive data, even if briefly exposed, can remain accessible through AI tools like Microsoft Copilot long after being made private. A cybersecurity firm, Lasso, found that thousands of once-public GitHub repositories from major companies, including Microsoft, remain accessible due to indexing by Bing’s search engine.

Lasso discovered this when content from its own private GitHub repository appeared in Copilot’s responses, despite the repository being set to private. This raised alarms about the risk of data retention by AI models, as even a short exposure can lead to long-term data leaks.

The investigation revealed that over 20,000 private GitHub repositories, belonging to more than 16,000 organizations, were still accessible through Copilot. Affected companies include Google, IBM, PayPal, Tencent, and Microsoft, among others. Some of these repositories contained confidential data, access keys, and intellectual property, making them a serious cybersecurity risk.

Microsoft was notified in November 2024 but classified the issue as low severity. While Bing’s cache links were removed in December 2024, Lasso found that Copilot could still retrieve the data, suggesting that the issue remains unresolved.

Companies are now being urged to rotate or revoke exposed access keys and take measures to protect sensitive data from AI-powered indexing. This incident highlights the growing risks of AI-driven data retention, reinforcing the need for better security measures in cloud and AI integrations.

Releated Posts

Why Throwing Away Batteries Can Start a Fire

Most people do not think twice before tossing old batteries into the bin. They are small. They seem…

ByByNipuni Tharanga Mar 13, 2026

How AI Is Learning to Read Our Inner Thoughts

Inside your brain, billions of neurons fire every second. They create patterns of electrical activity that form your…

ByByNipuni Tharanga Mar 4, 2026

Can a Machine Ever Love You Back? The Truth About AI Romance

People are falling in love with artificial intelligence. It sounds like something from a movie, but it is…

ByByNipuni Tharanga Feb 12, 2026

ChatGPT Now Shows Ads: What Free Users in the US Need to Know

OpenAI has started showing advertisements in ChatGPT for users in the United States. This change affects people using…

ByByNipuni Tharanga Feb 10, 2026

Leave a Reply

Your email address will not be published. Required fields are marked *