Snowflake flaw slips past AI checks, gets exploited by another AI
Brief
An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw.
The vulnerable code was part of a pull request (PR) that GitHub Copilot was involved in, though Wiz has clarified that it is unclear whether the coding assistant itself introduced the vulnerability. “Copilot was a co-author that checked the merged PR and code change, and identified it as all-clear without noticing the critical vulnerabilities,” Wiz researchers said in a blog post .
The attack path was identified and exploited using Wiz’s autonomous security research tool “Red Agent,” which ultimately managed to access Snowflake’s internal Jira credentials.
