Research · curated 10 Sep 2026

Red Agent Exploits Snowflake Vuln Missed by Github Copilot

Coverage timeline

discovered wiz.io primary 10 Sep 2026forbes.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Wiz Red Agent demonstrates that autonomous AI agents can now independently find and exploit real CI/CD vulnerabilities in the wild, even ones that passed automated security scans, foreshadowing an AI-versus-AI dynamic defenders must prepare for.

Wiz's autonomous AI security agent, Red Agent, discovered and exploited a script-injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net GitHub Actions workflow, letting an unauthenticated user run arbitrary commands by opening an issue with a crafted title, which Wiz used to access Snowflake's internal Jira via an exfiltrated token. The flaw was reported through Snowflake's HackerOne program and remediated on June 23, 2026; GitHub Advanced Security had scanned the vulnerable workflow without flagging it.