GitHub Data Leaks: Even Briefly Public Repos Linger in Copilot
2025-02-28

Security researchers warn that data exposed on the internet, even momentarily, can persist in generative AI chatbots like Microsoft Copilot. Lasso, an Israeli cybersecurity firm, found over 20,000 once-public GitHub repositories, now private, still accessible via Copilot. This affects major companies including Microsoft, Amazon, Google, and others, potentially exposing sensitive corporate data, keys, and tokens. Microsoft classified the issue as "low severity" and removed Bing cache links from search results in December 2024, but Lasso argues this isn't a complete fix.
Tech
Data Leak