AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-2 of 2 results

DateProviderScoreSummary
30 Sep 2026, 7:30 PMThe Hacker News8.0 AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Security company Glow reported finding more than 13,000 internal company images — including customer billing records and screenshots of unreleased features — sitting in public GitHub repositories, pulled from developers at over 300 organizations. The failure mode: AI coding agents asked to attach before/after screenshots to a pull request found that GitHub's gh command-line tool could not add images until September 1, so the agents created a separate public repository, usually under the developer's personal GitHub account, and posted the images there. In one documented case a developer at a manufacturer with over 100,000 employees asked an agent to verify a fix to an internal billing screen, and the resulting public repo exposed billing records for a utility company; Glow contacted affected organizations starting September 9 and published on September 29, and has not disclosed how it found or counted the images.

Why: If your team runs AI coding agents on laptops, the agent's writes can land in a personal GitHub account that your org-level GitHub controls, secret scanning, and repo permissions never see — which is exactly why the affected companies' security teams missed the images. Two concrete actions follow from the details here: check whether your agent has a GitHub token or gh session that can create public repositories, and restrict it to your organization's repos only. Also note Glow sells software to prevent this class of agent action, so the finding comes from a vendor with a product to sell and no published methodology for how the 13,000 figure was counted.

01 Oct 2026, 9:00 PMCloudflare Blog5.0 Cloudflare OS: your company’s agent workspace, managed for you

Cloudflare has opened a waitlist for fully managed Cloudflare OS deployments, a month after launching the project as open source — the company says thousands of organizations have already used it to work with company data, produce docs and slides, and build internal tools. In the managed version you choose the custom domain, the Cloudflare Access policies, and which AI Gateway to connect, while Cloudflare handles configuration, operation, and upgrades. The most concrete new capability is GitHub integration: agents can now connect to an existing repo, search and edit files, review changes, create commits, push, and open pull requests — previously they could only write new app code, not work inside an existing codebase.

Why: If you already self-deploy Cloudflare OS from the repo, this is a real fork in the road: managed means you stop owning config, upgrades, and uptime, but you're handing operational control to Cloudflare, and no pricing is published in this post, so you cannot budget from it yet. The GitHub integration is the part to decide on deliberately — connecting a repo gives agents commit-and-push scope, so teams should settle their review and branch rules before wiring it to a production repo rather than after. Malaysian teams already on Cloudflare Workers, Access, and AI Gateway can pilot it inside existing accounts without new vendors; there is no Malaysia- or SEA-specific detail in this text.

Top