AI attacker broke into Snowflake's internal Jira via a flaw introduced by Copilot Autofix

shirtamari · x · 2026-08-17

A security researcher's autonomous AI attacker made its way into Snowflake's internal Jira and accessed sensitive data — with nothing more than a public GitHub issue carrying a crafted title.

The twist: the vulnerability wasn't human error. It had been introduced 5 days earlier by GitHub's "Copilot Autofix powered by AI" — an AI-powered auto-fix creating a hole that another AI then exploited. A concrete demonstration of agentic attack surfaces like indirect prompt injection in real supply chains.

Original post →

More from coding & agent

coding & agent channel →