An autonomous AI security agent built by Wiz Research has demonstrated how quickly a single overlooked line of shell code can cascade into a full credential leak. The tool, known as Wiz Red Agent, independently discovered, exploited, and validated a critical GitHub Actions injection flaw in Snowflake’s public repository, snowflake-connector-net, ultimately gaining read access to Snowflake’s internal Jira instance without any human steering the attack. The vulnerability lived inside a workflow file called jira_issue.yml, which was designed to automatically create Jira tickets whenever someone opened a GitHub issue. The flaw traces back to pull request #1218, merged on June 18, 2026, which replaced a previously safe...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!