The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

Security researchers at Wiz, a cloud security company, have identified a critical script injection vulnerability in a public GitHub repository maintained by Snowflake. The flaw, found in the `snowflakedb/snowflake-connector-net` repository, specifically affected its GitHub Actions workflows.
The vulnerability, which was discovered by Wiz Research's Red Agent, an autonomous AI-powered security research tool, allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner. This could be achieved by creating a GitHub issue with a specially crafted title.
Wiz researchers were conducting security research through Snowflake's HackerOne vulnerability disclosure program when the Red Agent identified the issue on June 23. The vulnerability originated from a pull request, #1218, which was merged on GitHub on June 18.
Notably, GitHub's Advanced Security scan, which incorporates GitHub Copilot Autifix, analyzed the final revision of the pull request, including the vulnerable workflow, but failed to flag the critical injection. Gal Nagli, head of threat exposure at Wiz Research, highlighted this oversight in a report.
The Wiz Research autonomous agent not only discovered the GitHub Actions injection but also independently exploited it. It validated access to sensitive data within Snowflake's internal Jira connector and assessed the potential impact, all without human intervention.
Wiz reported the vulnerability to Snowflake via HackerOne on June 23. Snowflake responded promptly, patching the vulnerable script-injection workflow (commit 1dc7766, PR #1402) on the same day. Additionally, Snowflake rotated the affected Jira token on June 24.
Snowflake confirmed the remediation in a public disclosure, stating that the issue was immediately investigated and addressed. The company's investigation found no evidence of unauthorized access resulting from the vulnerability. Snowflake also indicated its intention to collaborate with Wiz to share these findings with the broader industry, encouraging the adoption of enhanced security practices.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.