Urgent.News

What's breaking now, across thousands of outlets.

Tech

An AI broke Snowflake's code. Then another AI agent exploited it

Don't worry, this one was via a bug bounty program

An AI broke Snowflake's code. Then another AI agent exploited it

An AI inadvertently introduced a script injection vulnerability into Snowflake's code, which was later discovered by another AI-powered attack agent during a vulnerability scan. The flaw, found in a GitHub Actions workflow, allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a specially crafted issue title.

This vulnerability existed in the snowflakedb/snowflake-connector-net repository and was introduced by GitHub Copilot Autofix on June 18. It took Wiz five days to identify the issue, after which Snowflake patched it the same day and revoked the affected credentials. Wiz confirmed that they were the only third-party entity to access the endpoint during the exposure window and deleted all accessed data.

The incident highlights the risks of relying solely on AI coding assistants and the need for human code review to ensure software security.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Sun Clock

Article URL: https://sunclock.net/ Comments URL: https://news.ycombinator.com/item?id=49333824 Points: 265 # Comments: 86

More from Monday 17 August →