An AI broke Snowflake's code. Then another AI agent exploited it
ID: 76d5df0e-1a58-5cdb-81c4-dafb19c1bf21
STIX ID: report--76d5df0e-1a58-5cdb-81c4-dafb19c1bf21
Feed Name: The Register (Security)
Threat Score
An AI-assisted commit by GitHub Copilot Autofix introduced a script-injection flaw in Snowflake's GitHub Actions workflow that allowed unauthenticated command execution via a crafted GitHub issue title. Wiz’s autonomous red-agent discovered and used the flaw in a sanctioned HackerOne bug bounty test to exfiltrate Jira credentials; Snowflake patched the workflow and rotated the token the same day and reported no evidence of unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
