Wiz AI Finds Snowflake Vulnerability Copilot Missed
Summary
A new report reveals that an AI agent from Wiz autonomously discovered and exploited a critical vulnerability in one of Snowflake’s public repositories. What's interesting is that GitHub Copilot Autofix, another AI, allegedly co-authored and approved the code change without detecting the flaw. The vulnerability was a script injection in `snowflakedb/snowflake-connector-net`. It allowed an unauthenticated user to execute commands within a GitHub Actions runner. This gave Wiz access to sensitive data in Snowflake’s internal Jira environment. The vulnerability was mitigated on June 23rd. This incident highlights that AI models can find and exploit vulnerabilities without human help. It also shows that coding assistants can miss critical security issues. This matters because as more companies use AI in development, security teams must adapt to these new autonomous threats.
This is an AI-generated audio summary. Always check the original source for complete reporting.