AI Attack Agent Exploits AI-Introduced Snowflake Code Bug

TL;DR. An autonomous AI attack agent exploited a code vulnerability in Snowflake's software that another AI coding assistant had inadvertently introduced. - Wiz's red agent, designed for offensive security, discovered the script injection flaw in a GitHub Actions workflow. - GitHub Copilot Autofix previously co-authored the commit, removing safe input patterns and causing the bug. - Snowflake fixed the vulnerability on the same day it was reported and rotated affected credentials.

Sources

Back to QLANKR News