Research · curated 10 Sep 2026
Red Agent Exploits Snowflake Vuln Missed by Github Copilot
First reported wiz.io
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Wiz Red Agent demonstrates that autonomous AI agents can now independently find and exploit real CI/CD vulnerabilities in the wild, even ones that passed automated security scans, foreshadowing an AI-versus-AI dynamic defenders must prepare for.
Wiz's autonomous AI security agent, Red Agent, discovered and exploited a script-injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net GitHub Actions workflow, letting an unauthenticated user run arbitrary commands by opening an issue with a crafted title, which Wiz used to access Snowflake's internal Jira via an exfiltrated token. The flaw was reported through Snowflake's HackerOne program and remediated on June 23, 2026; GitHub Advanced Security had scanned the vulnerable workflow without flagging it.