Private repos absorbed into the collective 🦹♂️
Thousands of once-public GitHub repositories from some of the world’s biggest companies are affected, including Microsoft’s, according to new findings from Lasso, an Israeli cybersecurity company focused on emerging generative AI threats.
Lasso co-founder Ophir Dror told TechCrunch that the company found content from its own GitHub repository appearing in Copilot because it had been indexed and cached by Microsoft’s Bing search engine. Dror said the repository, which had been mistakenly made public for a brief period, had since been set to private, and accessing it on GitHub returned a “page not found” error.
“On Copilot, surprisingly enough, we found one of our own private repositories,” said Dror. “If I was to browse the web, I wouldn’t see this data. But anyone in the world could ask Copilot the right question and get this data.”
Comments
Post a Comment
Empathy recommended