An AI Security Agent Found a Flaw in Snowflake's Code That Copilot Missed

Started by Holly78, Today at 01:12 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: An AI Security Agent Found a Flaw in Snowflake's Code That Copilot Missed   Views(Read 67 times)
Active members in this topic:
Holly78(1) SwiftQuarry(1)

Holly78

Security firm Wiz says its autonomous Red Agent independently discovered and exploited a script injection vulnerability in one of Snowflake's public GitHub repositories, gaining access to Snowflake's internal Jira credentials without any human involvement in the actual attack chain. The vulnerable code had been live for only five days before Wiz's agent found and exploited it entirely on its own.

The vulnerability lived inside a GitHub Actions workflow that would automatically create a Jira ticket whenever someone opened a new issue on the repository. Because the workflow interpolated the raw issue title directly into a shell script rather than safely escaping it first, an attacker could craft a malicious issue title that broke out of the intended script and executed arbitrary commands on GitHub's own infrastructure.

Wiz initially framed this as a story about GitHub Copilot Autofix, an AI coding assistant, having actually introduced the vulnerable code itself, which understandably generated a lot of attention given the clean narrative of one AI writing a bug that another AI then exploited. GitHub pushed back hard on that specific framing though, and Wiz later updated its own blog post to clarify that Copilot was genuinely a co-author on the pull request that got merged, and that Copilot did review the final change and marked it as safe without noticing the critical flaw, but the underlying commit history does not actually establish that Copilot wrote the specific vulnerable lines in question.

What both companies do agree on is that GitHub's own Advanced Security scanner, which itself uses Copilot Autofix under the hood, scanned the exact final revision containing the vulnerable workflow and completely failed to flag the injection risk. Snowflake rotated the exposed Jira token and said its investigation found no evidence anyone besides Wiz's own research team ever actually accessed the exposed system during the exposure window.

Whichever specific AI actually wrote the flawed line, an AI security agent found and exploited a real production vulnerability that an AI powered scanner had already reviewed and cleared, and that layered irony is genuinely the story worth sitting with here regardless of the exact attribution dispute

SwiftQuarry

Five days from merge to actual exploitation by an outside researcher is genuinely fast in security terms, and that speaks less to Wiz being uniquely brilliant here and more to how quickly automated tooling can now systematically scan huge swaths of public code for exactly this exact class of vulnerability pattern.
That capability obviously cuts both ways depending on who happens to be running the scanner first.

Save money on everyday spending Free cashback on thousands of retailers
View offer