Wiz's Red Agent autonomous AI discovered a flaw in Snowflake's GitHub Actions workflow that allowed it to enter the company's internal Jira instance. The agent authenticated as qa@snowflake.net using a token that provided read access to engineering, security compliance, and bug bounty projects.

GitHub's Copilot Autofix AI bot introduced the vulnerability five days before discovery by replacing a safer environment implementation with direct string interpolation. Snowflake deployed a fix on the same day Wiz disclosed the issue and used audit logs to confirm no other actors exploited the flaw during the exposure window.

Sign in to suggest edits

Key sources

  1. SOURCE@wiz_io“The flaw was created just 5 days earlier by GitHub's "Copilot Autofix" AI bot”x.com
  2. SUPPORT@wiz_io“confirmed Wiz's testing was the only activity during the exposure window”x.com
  3. SOURCE@galnagli“accessing sensitive data simply by opening a public GitHub issue with a crafted title”x.com
  4. SUPPORT@galnagli“The agent identified a GitHub Actions workflow in their public .NET connector”x.com
  5. SUPPORT@galnagli“The token had read access across engineering, security compliance and bug-bounty projects”x.com
  6. SUPPORT@galnagli“replaced it with direct string interpolation”x.com
Markdown