Thursday, 24 Sep 2026
Subscribe to AIWatcher
AIWatcher
  • Home
  • News

    OpenAI slots two cheaper GPT-6 models beneath Astra

    By
    AIWadmin

    Researcher hijacks Meta’s Muse agent through a hidden setting

    By
    AIWadmin

    ChatGPT learns to take voice orders for office chores

    By
    AIWadmin

    YouTube hands creators an AI agent for titles and thumbnails

    By
    AIWadmin

    Listeners can now rewrite the Spotify algorithm in plain words

    By
    AIWadmin

    Anthropic’s Claude agents flag a new enzyme family in viral DNA

    By
    AIWadmin
  • Articles

    Data shop Snorkel AI banks $350M as labs stockpile training sets

    By
    AIWadmin

    Ema banks $77M to push AI employees into the back office

    By
    AIWadmin

    US military command randomises routes to outfox enemy models

    By
    AIWadmin

    Kyutai teaches a speech model to do arithmetic out loud

    By
    AIWadmin

    Nokia hands developers a no-training route to calibrated answers

    By
    AIWadmin

    An open model sorts eight overlapping speakers in real time

    By
    AIWadmin
  • Spotlight

    DeepMind keeps cloud memory encrypted behind device-held keys

    By
    AIWadmin

    Anthropic trims Opus costs and speeds output in a mid-cycle refresh

    By
    AIWadmin

    Cisco Talos builds a fingerprint library for AI-driven malware

    By
    AIWadmin

    Google parks idle agents in a new open source runtime

    By
    AIWadmin

    OpenAI gives mathematicians a voice but hands them no brake

    By
    AIWadmin

    NVIDIA teaches its robotics stack to take instructions from agents

    By
    AIWadmin
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Hats
      • T-Shirts
    • Cart
  • 🔥
  • Alignment
  • Classification
  • Distillation
  • Explainability
  • Hallucination
  • Legal/Compliance
  • Medical
  • NLM
  • Mobility
  • Research
  • Robotics
  • Safety
  • Startups
  • Prompt
  • Python
  • RAG
  • RLHF
  • Token
  • Vision
Font ResizerAa
AIWatcherAIWatcher
  • Home
  • News
  • Articles
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News
  • Articles
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
News

Snowflake CI bug traced to an AI-generated security patch

A fix written by GitHub's AI autofix bot left Snowflake's CI pipeline open to command injection, Wiz Research says.

AIWadmin
Last updated: August 18, 2026 2:57 am
AIWadmin
ByAIWadmin
Global AI news & information.
Follow:
Share
SHARE

An AI bot’s suggested code fix turned into a live exploit within five days, according to research Wiz published Monday.

The trouble started June 18, when a pull request co-authored by Copilot Autofix, GitHub’s AI security-fix bot, landed in the public snowflake-connector-net repository. The change rewrote a GitHub Actions workflow called jira_issue.yml so that it pushed an issue’s title straight into a shell command, dropping an earlier pattern that kept untrusted text out of the shell. Anyone with a GitHub account could trigger the workflow, and a guard condition meant to limit who could never actually fired.

Snowflake learned of the hole on June 23, when Wiz’s autonomous research agent, Red Agent, exploited it through the company’s bug bounty program. The agent walked away with a Jira API token from the runner’s environment, after one failed payload that hit a bash syntax error and a second attempt with a revised one.

Snowflake fixed the workflow the same day it received the report, rotated the affected credential the next day, and told Wiz its audit logs showed no other actor reached the exposed systems during the five-day window.

The episode is a case study in the limits of AI-assisted patching: the suggestion mechanism delivered a plausible fix, and the human review step approved it without catching the security pattern it removed.

TAGGED:AI AgentsAI securityCI/CDGitHub CopilotSnowflakeVulnerabilityWiz
SOURCES:Unite AI
Share This Article
Email Copy Link Print
ByAIWadmin
Follow:
Global AI news & information.
Previous Article Groq banks $350M for a second act running Nvidia clouds
Next Article AI verifies the frontier result in the hunt for twin primes

You Might Also Like

News

Robot data startup Mecka draws Sequoia at a $500M value

By
AIWadmin
News

CoreWeave and Leidos team up on classified AI data centers

By
AIWadmin
News

ShinyHunters Tore Open Instructure’s Vault: 275 Million Student Records Exposed

By
AIWadmin
News

Musk’s AGI Claim Collapses Under Oath as OpenAI Trial Exposes His Contradictions

By
AIWadmin
AIWatcher
Facebook Twitter Youtube Linkedin Rss

Global AI News and Information
AIWatcher is your definitive source for AI updates worldwide, from Silicon Valley to Shanghai.
Our industry coverage keeps you in the loop with the latest news and trends shaping the future of AI.

Quick Links
  • News
  • Articles
  • Spotlight
  • Events
About Us
  • Mission
  • Services
  • Contact
  • Privacy Policy
  • Legal
© 2026 AIWatcher. All Rights Reserved.