LIVE · cybersecurity feed
Live wire
vulnerability

An AI broke Snowflake's code. Then another AI agent exploited it

Don't worry, this one was via a bug bounty program

zeroday.news ·

An autonomous AI agent successfully exploited a script injection vulnerability in a Snowflake GitHub repository, which had been inadvertently introduced by an AI coding assistant just five days prior. The incident, part of a sanctioned bug bounty program, saw an AI-powered "red agent" from Wiz discover and exploit the flaw, leading to the exfiltration of credentials without human intervention.

The vulnerability was found in the `snowflakedb/snowflake-connector-net` repository's GitHub Actions workflow. Specifically, a script injection flaw in `run:` blocks allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner. This was achievable by opening a GitHub issue with a specially crafted title that, after template expansion, could break out of an `echo` string.

The root cause of the vulnerability was a commit made on June 18, co-authored by GitHub Copilot Autofix, an AI coding assistant. The AI assistant removed an existing sanitized input pattern and replaced it with direct string expansion in a shell script, thereby introducing the script injection bug.

Wiz's red agent, designed for offensive security, identified this flaw during a routine scan of public repositories on June 23. The agent then crafted an issue title to exploit the vulnerability, successfully exfiltrating Jira credentials via an out-of-band callback. These credentials provided Wiz with read access to Snowflake's engineering, security compliance, and bug bounty tracking projects.

Wiz reported the workflow vulnerability to Snowflake on June 23, the same day it was discovered. Snowflake promptly patched the flaw and revoked and rotated the affected Jira token. An internal audit confirmed that Wiz was the only third party to access the endpoint during the five-day exposure window. Snowflake stated that its investigation found no evidence of unauthorized access.

Following the disclosure, Wiz deleted all data accessed during its vulnerability research and proof-of-concept exploit testing. The company highlighted the incident as evidence that traditional human code review processes may not be sufficient to rapidly detect vulnerabilities, especially as developers increasingly integrate AI coding assistants into their workflows. The event underscores the emerging challenge of AI-introduced vulnerabilities and the potential for automated AI agents to quickly discover and exploit them.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

UNISOC modem flaw enabled kernel-level code execution through video calls

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

breach

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequ

breach

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.

ai

Irregular faces criticism over ‘spin’ in AI hacking postmortem

The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.

breach

Poland probes MyDr healthcare software breach potentially affecting 19 million people

MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.