LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

zeroday.news ·

Security researchers at Wiz, a cloud security company, have identified a critical script injection vulnerability in a public GitHub repository maintained by Snowflake. The flaw, found in the `snowflakedb/snowflake-connector-net` repository, specifically affected its GitHub Actions workflows.

The vulnerability, which was discovered by Wiz Research's Red Agent, an autonomous AI-powered security research tool, allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner. This could be achieved by creating a GitHub issue with a specially crafted title.

Wiz researchers were conducting security research through Snowflake's HackerOne vulnerability disclosure program when the Red Agent identified the issue on June 23. The vulnerability originated from a pull request, #1218, which was merged on GitHub on June 18.

Notably, GitHub's Advanced Security scan, which incorporates GitHub Copilot Autifix, analyzed the final revision of the pull request, including the vulnerable workflow, but failed to flag the critical injection. Gal Nagli, head of threat exposure at Wiz Research, highlighted this oversight in a report.

The Wiz Research autonomous agent not only discovered the GitHub Actions injection but also independently exploited it. It validated access to sensitive data within Snowflake's internal Jira connector and assessed the potential impact, all without human intervention.

Wiz reported the vulnerability to Snowflake via HackerOne on June 23. Snowflake responded promptly, patching the vulnerable script-injection workflow (commit 1dc7766, PR #1402) on the same day. Additionally, Snowflake rotated the affected Jira token on June 24.

Snowflake confirmed the remediation in a public disclosure, stating that the issue was immediately investigated and addressed. The company's investigation found no evidence of unauthorized access resulting from the vulnerability. Snowflake also indicated its intention to collaborate with Wiz to share these findings with the broader industry, encouraging the adoption of enhanced security practices.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishinghigh

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Phishing, malvertising attacks could target devs to gain access to private corporate networks

vulnerabilitycritical

NASA Ground Control Software Flaw Enables Unauthenticated Commands

Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

breach

BGP Role model: tracking the adoption of RFC 9234

RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.

security

Meta Ran Ads for an App That Promised to Nudify Female Politicians

One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.

security

Hackers target Ukrainian agency managing assets seized from sanctioned Russians

The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.