wiz · Crawled Aug 17, 2026

Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix”

2 IoCs
Read original article ↗

AI Summary

Wiz Research's AI-powered Red Agent discovered a critical script injection vulnerability in a GitHub Actions workflow within Snowflake's public repository snowflakedb/snowflake-connector-net. The vulnerability was introduced on June 18, 2026, via an AI-generated 'autofix' commit that removed safe input handling, allowing unauthenticated users to execute arbitrary commands by opening a maliciously titled GitHub issue. Wiz successfully exploited the flaw to exfiltrate Snowflake's Jira API token, which granted read access to internal engineering and security projects. Snowflake patched the workflow, rotated credentials, and confirmed no unauthorized access occurred beyond Wiz's testing.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
IP 20[.]106[.]182[.]197 Details →
Domain subdomain[.]oast[.]me Details →