Technology

Copilot exposes private GitHub pages, some removed by Microsoft

Repositories once set to public and later to private, still accessible through Copilot.

Ars Technica

published: Feb 28, 2025

Blog Image

Microsoft’s Copilot AI assistant is exposing the contents of more than 20,000 private GitHub repositories from companies including Google, Intel, Huawei, PayPal, IBM, Tencent and, ironically, Microsoft.

These repositories, belonging to more than 16,000 organizations, were originally posted to GitHub as public, but were later set to private, often after the developers responsible realized they contained authentication credentials allowing unauthorized access or other types of confidential data. Even months later, however, the private pages remain available in their entirety through Copilot.

AI security firm Lasso discovered the behavior in the second half of 2024. After finding in January that Copilot continued to store private repositories and make them available, Lasso set out to measure how big the problem really was.

Read full article

Comments

Read More
AI
Biz & IT
Security
copilot
GitHub
private
public
search cashe

Stay in the loop

Never miss out on the latest insights, trends, and stories from Cedi Life! Be the first to know when we publish new articles by subscribing to our alerts.