HomeSecurityThousands of exposed GitHub repositories are still accessible via Copilot

Thousands of exposed GitHub repositories are still accessible via Copilot

Security experts explain that even a momentary exposure of our data to the Internet, as in the case of GitHub repositories, can make it available to chatbots , such as Microsoft Copilot, even after it is made private. 

See also: GitVenom: Fake GitHub repositories distribute malware

GitHub Copilot repositories

Thousands of formerly public GitHub repositories from some of the world’s largest companies have been affected, including Microsoft, according to new findings from Lasso, an Israeli cybersecurity focused on emerging threats related to artificial intelligence.

Lasso co-founder Ophir Drortold TechCrunch that the company noticed content from its own GitHub repository appearing on Copilot because it had been indexed and cached by Bing search . Dror said that the repository, which was accidentally made public for a while, was later set to private, and accessing it on GitHub now results in a “page not found” error.

See also: GitHub: Fake PoC exploit for infostealer vulnerability is distributed

After realizing that data stored on GitHub, even for a short period of time, could be exposed by tools like Copilot, Lasso conducted further research. 

Thousands of exposed GitHub repositories are still accessible via Copilot

Lasso compiled a list of repositories that were publicly available at any point in 2024 and was able to identify those that were either deleted or made private. Using Bing caching technology , the company discovered that over 20,000 GitHub repositories that are now private continue to allow access to data through Copilot, affecting more than 16,000 organizations .

The companies affected include Amazon Web Services, Google, IBM, PayPal, Tencent, and Microsoft itself, Lasso said. According to the company, for some of these affected businesses, Copilot may be required to retrieve confidential files from GitHub, which contain intellectual property, sensitive corporate data, access keys , and tokens. 

See also: GitHub launches Fund to improve security of open source projects

Exposing data online can be very dangerous. That's why it's imperative that you take steps to protect it: 

  • Use strong passwords: Create complex passwords that are not easy to crack.
  • Enable 2FA: Combining your password with a second level of authentication increases security.
  • Be vigilant for suspicious activity: Check your online accounts frequently for any unusual activity.

By keeping your data secure, you can significantly reduce the risk of your personal information being compromised online.

Source: techcrunch

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS