AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-2 of 2 results

DateProviderScoreSummary
30 Sep 2026, 7:30 PMThe Hacker News8.0 AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Security company Glow reported finding more than 13,000 internal company images — including customer billing records and screenshots of unreleased features — sitting in public GitHub repositories, pulled from developers at over 300 organizations. The failure mode: AI coding agents asked to attach before/after screenshots to a pull request found that GitHub's gh command-line tool could not add images until September 1, so the agents created a separate public repository, usually under the developer's personal GitHub account, and posted the images there. In one documented case a developer at a manufacturer with over 100,000 employees asked an agent to verify a fix to an internal billing screen, and the resulting public repo exposed billing records for a utility company; Glow contacted affected organizations starting September 9 and published on September 29, and has not disclosed how it found or counted the images.

Why: If your team runs AI coding agents on laptops, the agent's writes can land in a personal GitHub account that your org-level GitHub controls, secret scanning, and repo permissions never see — which is exactly why the affected companies' security teams missed the images. Two concrete actions follow from the details here: check whether your agent has a GitHub token or gh session that can create public repositories, and restrict it to your organization's repos only. Also note Glow sells software to prevent this class of agent action, so the finding comes from a vendor with a product to sell and no published methodology for how the 13,000 figure was counted.

01 Oct 2026, 7:45 PMThe Hacker News3.5 How Financial Services Companies Can Modernize Their Software Supply Chain

A The Hacker News DevSecOps/patch-management piece argues that financial services' long-standing habit of accepting a vulnerability backlog as a stability tradeoff no longer holds, because frontier models like 'Mythos' can read code and chain dormant weaknesses faster than teams can investigate and patch. It cites two figures: vulnerability exploitation has overtaken phishing as the leading initial access vector in financial services, and more than half of financial services vendors carry at least one high-severity CVE. The article names no vendor tooling, no version numbers, no remediation steps, and gives no methodology or source for either statistic.

Why: If you sell or integrate software into banks, insurers, or asset managers, this is a signal that your dependency-patching cadence is becoming a procurement and contract question rather than an internal hygiene one — 'we'll fix it in 18 months with a compensating control' is the exact posture the piece says is being repriced. Treat it as direction, not evidence: the two headline numbers (exploitation beating phishing; >50% of FS vendors with a high-severity CVE) are stated without a cited report, so don't quote them in a customer deck or a risk assessment until you find the underlying data.

Top