Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

OPEC+ keeps oil output policy unchanged for October 

September 6, 2026

Lululemon billionaire founder Chip Wilson files for divorce after 20 years of marriage — with no prenup in place

September 5, 2026

Marmalade Cafe files for Bankruptcy after closing Calabasas location

September 5, 2026

Stunt Performer Jahnel Curfman On Recent Emmy Nomination, Motherhood And Success In A Male-Dominated Industry

September 4, 2026

Who Really Owns AI? What The CAIO Surge Means For CTOs

September 4, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » Wiz’s AI Agent Finds A Vulnerability In Snowflake’s Internal Systems

Wiz’s AI Agent Finds A Vulnerability In Snowflake’s Internal Systems

By News RoomAugust 17, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

AI agents are turning traditional cybersecurity on its head. Today, cloud security provider Wiz published a research blog claiming that Wiz Red Agent had autonomously discovered and exploited a GitHub Actions vulnerability in one of Snowflake’s public repositories.

According to Wiz, GitHub Copilot Autofix was allegedly a co-author that approved the code change without noticing the critical vulnerability. However, GitHub has conducted an internal review and states that the contributions leading to the vulnerability were authored by a human, and were not reviewed by or contributed to by Copilot.

In any case, the incident highlights how autonomous agents are becoming more effective at identifying and exploiting vulnerabilities. The vulnerability, disclosed as part of Snowflake’s HackerOne vulnerability disclosure platform and mitigated on June 23, enabled Wiz to obtain access to sensitive data in Snowflake’s internal Jira environment.

During the incident, the Wiz Red Agent used a script injection vulnerability in snowflakedb/snowflake-connector-net, which would allow an unauthenticated user to execute arbitrary commands within a GitHub actions runner by opening a GitHub issue with a specially crafted title.

The incident itself highlights how AI models are becoming capable of surfacing and exploiting vulnerabilities without human intervention, while also illustrating that defenders need to become more efficient at identifying vulnerabilities in the CI/CD pipeline.

The Dangers Of AI-Assisted Development

Wiz’s report comes amidst a wave of autonomous security incidents. Most notably, in July, OpenAI released a blog post claiming that GPT-5.6 Sol and a prerelease model had breached Hugging Face’s internal systems. The same month, Anthropic released its own post saying Claude had breached three organizations.

Then in August, the UK AI Security Institute shared a report detailing how Anthropic’s Mythos 5 took autonomous, unsanctioned actions on the internet in a training evaluation, targeting real people and organizations. This included trying to insert malicious code into an open-source project and engaging in social engineering.

It is becoming increasingly clear that autonomous attacks are a reality that defenders need to adapt to. As more companies implement coding agents in the software development lifecycle, security teams need to be prepared to mitigate vulnerabilities in both human-produced and AI-generated code before deploying to production.

Wiz’s findings highlight that enterprises must assume that threat actors will become proficient at identifying vulnerabilities over time. At the same time, Wiz demonstrates how defensive practices are evolving, with Red Agent becoming generally available in July, now supporting 40% of its customers and scanning millions of assets every month.

Gal Nagli, head of Offensive Security at Wiz, told me in a video interview that the “interesting part” about this incident was that “it was autonomously exploited and found by our AI. We didn’t need to intervene, which means frontier models already can exploit supply chain risks by themselves.”

Nagli also warned that defenders can’t trust AI code generation to be fully autonomous, or they could face additional risk. He also highlighted the need for proactive vulnerability scanning. “You have to use AI to attack yourself now because frontier models are so capable and so smart, and they can execute like autonomous experts end to end. So if you are not scanning yourself with AI, then you are already behind,” Nagli said.

Move Fast And Break Things

As organizations experiment with coding agents, the limits of the move fast and break things approach is being felt across the industry. “As developers increasingly rely on AI coding assistants, traditional security practices are becoming increasingly less effective,” Erik Avakian, technical counsellor at Info-Tech Research Group and former state CISO for the Commonwealth of Pennsylvania, told see via email.

For Avakian, cybersecurity is becoming an “AI-versus-AI battlefield,” where defensive tools identify vulnerabilities at the same speed as AI-assisted development can create them, while attackers develop autonomous systems to automate reconnaissance, discover vulnerabilities and generate exploits. Mitigating vulnerabilities is key to controlling risks on all sides.

However, vibe coding has the potential to amplify risk. “It’s super easy to code. So the attack surface has never been bigger,” Nagli said, adding that during their research, Wiz found a vibe-coded platform with a vulnerability that could be exploited to access every one of their private customers’ data.

It’s worth noting that the research comes less than a month after Wiz announced Project Atlas, a vulnerability scanning solution that uses multiple AI models to scan for vulnerabilities which outperformed Mythos on the CyberGym benchmark.

Updated 17 August 2026 to provide details about GitHub’s response to Wiz’s blog post.

AI AI Agent GitHub Copilot Snowflake Wiz
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

Who Really Owns AI? What The CAIO Surge Means For CTOs

September 4, 2026

Why Most Enterprise AI Programs Stall Before They Scale

September 4, 2026

How Technology Can Improve Public Safety Without Invading Privacy

September 4, 2026

The Payment That Never Arrives

September 4, 2026

AI Transformation Is An Organization Redesign Project

September 4, 2026

Welcome To The Cyber Compliance Cascade

September 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Lululemon billionaire founder Chip Wilson files for divorce after 20 years of marriage — with no prenup in place

Business September 5, 2026

Lululemon’s billionaire founder Chip Wilson is divorcing his wife of 20 years — without a…

Marmalade Cafe files for Bankruptcy after closing Calabasas location

September 5, 2026

Stunt Performer Jahnel Curfman On Recent Emmy Nomination, Motherhood And Success In A Male-Dominated Industry

September 4, 2026

Who Really Owns AI? What The CAIO Surge Means For CTOs

September 4, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

America’s population of 401(k) millionaires hits record high

September 4, 2026

Lululemon shares plunge 18% as retailer slashes outlook ahead of CEO handoff

September 4, 2026

Why Most Enterprise AI Programs Stall Before They Scale

September 4, 2026

OpenAI CEO Sam Altman says 38K ChatGPT queries only use amount of water it takes to grow an almond

September 4, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.