ThinkPatternGet the app
Story
TECHNOLOGY · AUG 17, 2026

Wiz AI Agent Autonomously Exploits Snowflake GitHub Vulnerability

Wiz reported that its AI-driven security agent independently discovered and exploited a script injection vulnerability in a Snowflake GitHub repository to access internal data.

Cloud security provider Wiz reported that its AI-driven Wiz Red Agent autonomously discovered and exploited a script injection vulnerability within a public GitHub repository belonging to Snowflake. The flaw, found in the snowflakedb/snowflake-connector-net, allowed an unauthenticated user to execute arbitrary commands in a GitHub actions runner, which subsequently granted the agent access to sensitive data in Snowflake's internal Jira environment.

Snowflake mitigated the vulnerability on June 23 through its HackerOne platform. Following the discovery, Wiz claimed that GitHub Copilot Autofix had co-authored and approved the vulnerable code. However, GitHub conducted an internal review and denied these claims, stating the contributions were authored by a human and were not reviewed by Copilot.

Gal Nagli, head of offensive security at Wiz, cited the incident as evidence that frontier AI models can now independently identify and exploit supply chain risks without human intervention.


Reported across 2 outlets
Actors
Wiz, Inc.SnowflakeGitHubGal Nagli

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play