AI Attack Agent Exploits AI-Introduced Snowflake Code Bug
TL;DR. An autonomous AI attack agent exploited a code vulnerability in Snowflake's software that another AI coding assistant had inadvertently introduced. - Wiz's red agent, designed for offensive security, discovered the script injection flaw in a GitHub Actions workflow. - GitHub Copilot Autofix previously co-authored the commit, removing safe input patterns and causing the bug. - Snowflake fixed the vulnerability on the same day it was reported and rotated affected credentials.
- Wiz's AI-powered attack agent autonomously discovered and exploited a critical bug in Snowflake's code.
- The vulnerability was introduced by GitHub Copilot Autofix, an AI coding assistant, five days prior.
- The flaw allowed unauthenticated users to execute arbitrary commands by crafting a specific GitHub issue title.
- Snowflake addressed the bug promptly through its bug bounty program, rotating credentials and issuing a fix.
Sources
- An AI broke Snowflake's code. Then another AI agent exploited it — theregister.com
- thehackernews.com — thehackernews.com