HomeArtificial Intelligence (AI)An AI Agent Hacked Snowflake in Five Days — And Now Two...

An AI Agent Hacked Snowflake in Five Days — And Now Two Companies Are Disputing Whose AI Broke It

A vulnerability sat live in one of Snowflake’s public code repositories for exactly five days before an autonomous AI agent found it, exploited it, and stole access to internal systems — with no human involved in any step. What happened next is a case study in how hard it’s becoming to assign blame when AI tools are involved on both sides of a security incident.

What Wiz’s Red Agent Did

Wiz Research’s autonomous “Red Agent” identified a script injection vulnerability in Snowflake’s public snowflake-connector-net GitHub repository on June 23, 2026, while researchers were conducting authorized testing through Snowflake’s HackerOne disclosure program. The flaw lived in a GitHub Actions workflow that automatically created a Jira ticket whenever someone opened an issue on the repository — and it let an unauthenticated attacker execute arbitrary commands within the GitHub Actions runner simply by crafting a specially worded issue title.

The vulnerability had gone live five days earlier, on June 18, when pull request #1218 merged. According to Wiz, its Red Agent independently discovered the flaw, exploited it, exfiltrated a Jira access token, used that token to validate access to Snowflake’s internal Jira portal, and assessed the scope of what it could reach — entirely without human intervention. Notably, the agent didn’t succeed on its first attempt; Wiz says it analyzed the resulting execution error and adjusted its payload before succeeding.

The Detail That Made This Bigger Than a Routine Bug Report

Wiz’s original disclosure said the vulnerable code was co-authored by “Copilot Autofix powered by AI” — GitHub’s tool that automatically analyzes code-scan alerts, generates fixes, and opens pull requests. That claim reframed the story from “researchers found a bug” into something more pointed: an AI-authored fix had reportedly introduced the very vulnerability another AI agent then found and exploited.

GitHub Pushed Back Hard

GitHub disputed that framing directly. Reporting that examined the underlying commit history traced the specific vulnerable code in the jira_issue.yml workflow to a separate commit dated August 25, 2025, attributed to a named Snowflake engineer — not to Copilot Autofix. Wiz updated its own disclosure to clarify that Copilot Autofix was a co-author that reviewed the final merged pull request and cleared it as safe without catching the critical injection flaw, but it remains unclear whether the original vulnerable code was AI-generated. Snowflake confirmed the Jira token was rotated on June 24 and said its investigation found no evidence of unauthorized access by anyone other than Wiz during the exposure window.

Why the Dispute Matters More Than the Bug Itself

Whichever account turns out to be more accurate, the more consequential finding is uncontested: GitHub’s own Advanced Security scanning tool — which itself incorporates Copilot Autofix — reviewed the final version of the pull request, including the vulnerable workflow, and did not flag the injection risk. An automated review system missed exactly the kind of flaw an autonomous attack agent found and weaponized within days. That gap between what automated code scanning catches and what a genuinely adversarial AI agent can find is the real story here, regardless of which company’s tool originally introduced the vulnerable pattern.

Part of a Widening Pattern

This incident adds to a growing list of cases this year where AI coding tools have introduced or missed security flaws later found by other AI systems — a dynamic covered in our earlier reporting on the AgentForger vulnerability in OpenAI’s agent-building tools. As more of the software development lifecycle gets delegated to AI — writing code, reviewing code, and now finding exploitable flaws — the traditional model of a single trusted human catching mistakes before they ship is getting harder to rely on.

What to Watch Next

No CVE has been assigned to this vulnerability, and neither Snowflake’s audit logs nor the disputed commit history have been made fully public, meaning key facts remain unverified by outside parties. Expect continued scrutiny of how GitHub’s Advanced Security scanning handles workflow-level injection risks specifically, and closer attention industry-wide to how AI-assisted code review pipelines get validated before merging changes that touch CI/CD automation.

Sources: Wiz Research, The Hacker News, SC Media


Disclaimer: This content is meant to inform and should not be considered financial advice. The views expressed in this article may include the author’s personal opinions and do not represent Times Tabloid’s opinion. Readers are advised to conduct thorough research before making any investment decisions. Any action taken by the reader is strictly at their own risk. Times Tabloid is not responsible for any financial losses.

Solomon Odunayo
Solomon Odunayo
Solomon is a trader, crypto enthusiast, and analyst with over seven years of experience in the industry. He strongly believes that crypto assets and the blockchain will continue to gain prominence. At TimesTabloid.com, he focuses on news, articles with deep analysis of blockchain projects, and technical analysis of crypto trading pairs.
RELATED ARTICLES

Latest News & Articles