GitHub pushes back on the story that its AI tool wrote a vulnerability Wiz found

Started by PhotonBurst17, Today at 03:13 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: GitHub pushes back on the story that its AI tool wrote a vulnerability Wiz found   Views(Read 57 times)
Active members in this topic:
PhotonBurst17(1)

PhotonBurst17

A dispute has broken out between GitHub and security firm Wiz over exactly who or what actually wrote the vulnerable code at the center of last week's Snowflake security research story, and the disagreement is a genuinely instructive example of how quickly a compelling AI narrative can spread before the underlying facts get fully nailed down. Wiz's original post framed GitHub Copilot Autofix, an AI tool designed to catch and fix security bugs, as having introduced the exact vulnerability that Wiz's own autonomous Red Agent later discovered and exploited, a framing that made for an obviously irresistible headline about AI tools failing each other.

GitHub disputed that framing directly and fairly forcefully. The company said its internal review of the commit history found that the contribution which actually introduced the vulnerability was authored by a human, and that Copilot Autofix neither reviewed nor contributed to that specific change in any capacity. That is a meaningfully different claim than what most of the initial coverage had already run with by the time GitHub's response became public.

Wiz updated its own post the same evening, softening the original claim considerably. The revised version, timestamped later that day, now describes Copilot as a co author that reviewed the already merged pull request and marked it clear without catching the underlying vulnerability, rather than having actually written the flawed code itself in the first place. Wiz's update goes on to add that it remains unclear whether the code change itself was AI assisted at all, a line that quietly undercuts a significant chunk of the original story that had already been widely republished across multiple outlets before that correction ever surfaced.

The damage from the initial framing had already spread fast by that point. The Register reportedly published the stronger AI wrote the bug version of the story before the correction landed, then updated its own headline later that night from an AI breaking the code to an AI failing to detect it, appending a formal correction and an editor's note acknowledging the error. That kind of public retraction from an established outlet is relatively rare and speaks to how confidently the original framing had been presented before anyone had actually dug into the underlying commit history.

No formal CVE identifier has been assigned to this vulnerability, and there's no independently confirmed evidence that anyone besides Wiz's own research team ever actually exploited it in a live environment. The underlying technical finding itself, that a script injection flaw sat in a public GitHub Actions workflow for five days before being discovered, remains valid and genuinely concerning on its own merits regardless of exactly who wrote the original flawed commit. But the authorship dispute is a pretty clean case study in how much faster a dramatic AI failure narrative travels compared to the far more mundane correction that inevitably follows it

Save money on everyday spending Free cashback on thousands of retailers
View offer