{"id":152460,"date":"2025-02-26T10:02:14","date_gmt":"2025-02-26T10:02:14","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/02\/26\/thousands-of-exposed-github-repos-now-private-can-still-be-accessed-through-copilot-techcrunch\/"},"modified":"2025-02-26T10:02:14","modified_gmt":"2025-02-26T10:02:14","slug":"thousands-of-exposed-github-repos-now-private-can-still-be-accessed-through-copilot-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/02\/26\/thousands-of-exposed-github-repos-now-private-can-still-be-accessed-through-copilot-techcrunch\/","title":{"rendered":"Thousands of exposed GitHub repos, now private, can still be accessed through Copilot | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Security researchers are warning that data exposed to the internet,\u00a0even for a moment, can linger in online generative AI chatbots like Microsoft Copilot long after the data is made private.<\/p>\n<p class=\"wp-block-paragraph\">Thousands of once-public GitHub repositories from some of the world\u2019s biggest companies are affected, including Microsoft\u2019s, according to new findings from Lasso, an Israeli cybersecurity company focused on emerging generative AI threats.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Lasso co-founder Ophir Dror told TechCrunch that the company found content from its own GitHub repository appearing in Copilot because it had been indexed and cached by Microsoft\u2019s Bing search engine. Dror said the repository, which had been mistakenly made public for a brief period, had since been set to private, and accessing it on GitHub returned a \u201cpage not found\u201d error.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOn Copilot, surprisingly enough, we found one of our own private repositories,\u201d said Dror. \u201cIf I was to browse the web, I wouldn\u2019t see this data. But anyone in the world could ask Copilot the right question and get this data.\u201d<\/p>\n<p class=\"wp-block-paragraph\">After it realized that any data on GitHub, even briefly, could be potentially exposed by tools like Copilot, Lasso investigated further.<\/p>\n<p class=\"wp-block-paragraph\">Lasso extracted a list of repositories that were public at any point in 2024 and identified the repositories that had since been deleted or set to private. Using Bing\u2019s caching mechanism, the company found more than 20,000 since-private GitHub repositories still had data accessible through Copilot, affecting more than 16,000 organizations. <\/p>\n<p class=\"wp-block-paragraph\">Affected organizations include Amazon Web Services, Google, IBM, PayPal, Tencent, and Microsoft itself, according to Lasso. For some affected companies, Copilot could be prompted to return confidential GitHub archives that contain intellectual property, sensitive corporate data, access keys, and tokens, the company said. <\/p>\n<p class=\"wp-block-paragraph\">Lasso noted that it used Copilot to retrieve the contents of a GitHub repo \u2014 since deleted by Microsoft \u2014 that <a href=\"https:\/\/techcrunch.com\/2025\/01\/10\/microsoft-accuses-group-of-developing-tool-to-abuse-its-ai-service-in-new-lawsuit\/\" target=\"_blank\" rel=\"noopener\">hosted a tool allowing the creation of \u201coffensive and harmful\u201d AI images<\/a> using Microsoft\u2019s cloud AI service.<\/p>\n<p class=\"wp-block-paragraph\">Dror said that Lasso reached out to all affected companies who were \u201cseverely affected\u201d by the data exposure and advised them to rotate or revoke any compromised keys.<\/p>\n<p class=\"wp-block-paragraph\">None of the affected companies named by Lasso responded to TechCrunch\u2019s questions. Microsoft also did not respond to TechCrunch\u2019s inquiry.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Lasso informed Microsoft of its findings in November 2024. Microsoft told Lasso that it classified the issue as \u201clow severity,\u201d stating that this caching behavior was \u201cacceptable,\u201d Microsoft <a rel=\"nofollow noopener\" href=\"https:\/\/searchengineland.com\/bing-officially-removes-cache-link-from-search-results-449220\" target=\"_blank\">no longer included links to Bing\u2019s cache<\/a> in its search results starting December 2024.<\/p>\n<p class=\"wp-block-paragraph\">However, Lasso says that though the caching feature was disabled,\u00a0Copilot still had access to the data even though it was not visible through traditional web searches, indicating a temporary fix.\u00a0<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/02\/26\/thousands-of-exposed-github-repos-now-private-can-still-be-accessed-through-copilot\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers are warning that data exposed to the internet,\u00a0even for a moment, can linger in online generative AI chatbots like Microsoft Copilot long after the data is made private. Thousands of once-public GitHub repositories from some of the world\u2019s biggest companies are affected, including Microsoft\u2019s, according to new findings from Lasso, an Israeli cybersecurity [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":152461,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-152460","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/152460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=152460"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/152460\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/152461"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=152460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=152460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=152460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}