{"slug": "wiz-red-agent-accessed-snowflake-jira-5-days-after-copilot-checked-flaw-went", "title": "Wiz Red Agent accessed Snowflake Jira 5 days after Copilot-checked flaw went live", "summary": "Wiz's autonomous AI agent Red Agent discovered and exploited a GitHub Actions script injection vulnerability in Snowflake's CI/CD pipeline, exfiltrating internal Jira access credentials just five days after the flaw was merged in a pull request co-authored by GitHub Copilot and cleared by GitHub Advanced Security. The exploit allowed an unauthenticated attacker to execute arbitrary code in the GitHub Actions runner, highlighting that AI-assisted code review can miss critical security flaws.", "body_md": "[Hacker News](https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug)\n\n### Wiz Red Agent accessed Snowflake Jira 5 days after Copilot-checked flaw went live\n\nWhich summary reads better? Pick one — models revealed after.Both summaries are AI-generated.\n\nGitHub Copilot Autofix approved a PR that introduced a command-injection flaw in Snowflake’s CI/CD pipeline, letting an unauthenticated attacker execute arbitrary code in their GitHub Actions runner. This means AI-assisted PRs can silently add critical security holes that bypass GitHub Advanced Security scans, so every merged PR—even those marked “safe” by Copilot—now needs a second, manual shell-injection review before deployment.\n\nAn autonomous AI agent discovered and exploited a GitHub Actions script injection vulnerability to exfiltrate internal Jira access credentials just five days after the flaw was merged in a pull request co-authored by GitHub Copilot and cleared by GitHub Advanced Security. This milestone demonstrates that AI agents can now execute end-to-end exploit chains in the wild faster than typical human patch cycles can secure AI-assisted code. If you are shipping with LLM-based coding agents or autofixers, you must immediately enforce hard boundary isolation and least-privilege token scoping on your CI/CD runners, as traditional static scanners and AI reviewers are actively failing to detect these injection vectors.", "url": "https://wpnews.pro/news/wiz-red-agent-accessed-snowflake-jira-5-days-after-copilot-checked-flaw-went", "canonical_source": "https://www.snipvote.com/story/cmsyc94tl0008josbsa5tiv3y", "published_at": "2026-08-18 07:41:43.726084+00:00", "updated_at": "2026-08-18 07:41:45.504444+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy", "ai-tools", "ai-products"], "entities": ["Wiz", "Red Agent", "Snowflake", "GitHub Copilot", "GitHub Advanced Security", "Jira"], "alternates": {"html": "https://wpnews.pro/news/wiz-red-agent-accessed-snowflake-jira-5-days-after-copilot-checked-flaw-went", "markdown": "https://wpnews.pro/news/wiz-red-agent-accessed-snowflake-jira-5-days-after-copilot-checked-flaw-went.md", "text": "https://wpnews.pro/news/wiz-red-agent-accessed-snowflake-jira-5-days-after-copilot-checked-flaw-went.txt", "jsonld": "https://wpnews.pro/news/wiz-red-agent-accessed-snowflake-jira-5-days-after-copilot-checked-flaw-went.jsonld"}}