Wiz Red Agent Hacks Into Snowflake's Internal Jira via a Copilot Autofix Bug

jedisct1 · x · 2026-08-17

Wiz Research's autonomous security tool Red Agent independently discovered and exploited a GitHub Actions script-injection flaw in Snowflake's public repo snowflake-connector-net through Snowflake's HackerOne program, validating access to sensitive data in Snowflake's internal Jira.

Key details:

Full write-up on the Wiz blog. A telling snapshot of the new reality: AI coding assistants introducing vulnerabilities while AI agents autonomously find them.

Related event: AI Attack Agent Breaches Snowflake's Internal Jira(2 posts)→

Original post →

More from coding & agent

coding & agent channel →