{"id":741310,"date":"2026-08-18T00:08:14","date_gmt":"2026-08-18T00:08:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/741310\/"},"modified":"2026-08-18T00:08:14","modified_gmt":"2026-08-18T00:08:14","slug":"an-ai-failed-to-detect-a-bug-in-snowflakes-code-then-another-ai-agent-exploited-it","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/741310\/","title":{"rendered":"An AI failed to detect a bug in Snowflake&#8217;s code. Then another AI agent exploited it"},"content":{"rendered":"<p class=\"kicker \" style=\"\">Security<\/p>\n<p class=\"subtitle \" style=\"\">Don&#8217;t worry, this one was via a bug bounty program<\/p>\n<p>Update 08\/18, 0000 GMT: Following publication, Wiz updated its blog post to explain that it wasn&#8217;t sure that Copilot Autofix introduced the error. It was listed as a co-author on the commit, but Wiz now says that it&#8217;s possible a human introduced the error, and that Autofix simply failed to correct it. The Register\u00a0regrets this error, has updated this story to reflect the revised information, and won&#8217;t be trusting Wiz for a very long time.\u00a0<\/p>\n<p>Original story below:<\/p>\n<p>An AI broke Snowflake\u2019s code; then another AI, an attack agent, autonomously found the bug, exploited it, and extracted credentials without human intervention.<\/p>\n<p>Luckily, this wasn\u2019t <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/06\/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack\/5283741\" rel=\"nofollow noopener\" target=\"_blank\">yet another<\/a> <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/08\/10\/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list\/5285591\" rel=\"nofollow noopener\" target=\"_blank\">case<\/a> of <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/31\/anthropic-and-openai-are-competing-to-see-whose-agents-can-go-rogue-harder\/5281797\" rel=\"nofollow noopener\" target=\"_blank\">rogue AI agents<\/a> <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/14\/autonomous-ai-attacks-pose-clear-and-present-danger-to-critical-infrastructure\/5287594\" rel=\"nofollow noopener\" target=\"_blank\">doing evil things<\/a>. It was a sanctioned bug hunt, conducted through Snowflake\u2019s HackerOne vulnerability disclosure program, and Snowflake fixed the flaw the same day Wiz reported it and rotated the affected credentials the following day.<\/p>\n<p>Wiz\u2019s <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/22\/google-unleashes-even-more-ai-security-agents-to-fight-crims\/5221298\" rel=\"nofollow noopener\" target=\"_blank\">red agent<\/a>, an AI-powered autonomous attacker designed for offensive security, found the GitHub Actions workflow flaw during a routine scan of public repositories on June 23. The script injection vulnerability existed in <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\" rel=\"nofollow noopener\" target=\"_blank\">snowflakedb\/snowflake-connector-net<\/a>, and it allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title.<\/p>\n<p>And it turned out an AI had inadvertently injected the bug into the code five days earlier.<\/p>\n<p>GitHub Copilot Autofix, an AI coding assistant, <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/pull\/1218\" rel=\"nofollow noopener\" target=\"_blank\">co-authored the commit<\/a> on June 18, and that commit introduced a script injection bug in run: blocks by removing the repository\u2019s existing sanitized input pattern and replacing it with direct string expansion in a shell script.<\/p>\n<p>\u201cWe crafted an issue title that, after template expansion, breaks out of the echo string and exfiltrates the Jira credentials via an out-of-band callback,\u201d Wiz\u2019s head of threat exposure Gal Nagli <a href=\"https:\/\/www.wiz.io\/blog\/red-agent-snowflake-copilot-cicd-bug\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> in a Monday blog.\u00a0<\/p>\n<p>These credentials gave Wiz read access to Snowflake\u2019s engineering, security compliance, and bug bounty tracking projects.<\/p>\n<p>Wiz reported the workflow vulnerability to the cloud data platform on June 23, and Snowflake patched it the same day. It also revoked and rotated the Jira token, and confirmed, via audit logs, that Wiz was the only third-party to access the endpoint during the five-day exposure window.\u00a0<\/p>\n<p>The disclosure \u201cwas immediately investigated and remediated, and our investigation found no evidence of unauthorized access,\u201d a Snowflake spokesperson told The Register. \u201cWe are working together with Wiz to share these learnings with the broader industry to encourage widespread adoption of these security best practices.\u201d<\/p>\n<p>Wiz, for its part, deleted all of the data it accessed during the vulnerability research and proof-of-concept exploit testing, and told us that this incident proves human code review isn\u2019t sufficient to quickly detect vulnerabilities &#8211;\u00a0 especially as developers increasingly use AI.<\/p>\n<p>\u201cThis incident highlights a rapidly emerging reality in software development: how AI coding assistants can inadvertently introduce workflow injection vulnerabilities, and how automated AI agents can rapidly surface them in the wild,\u201d Nagli wrote.<\/p>\n<p>Of course, the Google-owned biz has a vested interest in saying this. But this doesn\u2019t make it not true.\u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Security Don&#8217;t worry, this one was via a bug bounty program Update 08\/18, 0000 GMT: Following publication, Wiz&hellip;\n","protected":false},"author":2,"featured_media":741311,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-741310","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/741310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=741310"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/741310\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/741311"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=741310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=741310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=741310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}