{"data":{"id":"9147372e-9b2d-41a6-8dee-1e4ab8a575fb","title":"Snowflake flaw slips past AI checks, gets exploited by another AI","summary":"GitHub Copilot failed to catch a critical vulnerability in Snowflake's code during a review, but an autonomous AI security agent called Red Agent developed by Wiz successfully identified and exploited the flaw. The vulnerability was a command injection (allowing attackers to insert malicious commands into a workflow) in Snowflake's GitHub Actions pipeline that let attackers access internal Jira credentials, though Snowflake patched it the same day it was reported and found no evidence of unauthorized access.","solution":"Snowflake patched the workflow on June 23 by restoring the safer input-handling pattern and rotated the affected Jira credential the following day.","labels":["security","safety"],"sourceUrl":"https://www.csoonline.com/article/4211501/snowflake-flaw-slips-past-ai-checks-gets-exploited-by-another-ai.html","publishedAt":"2026-08-19T11:09:07.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Snowflake","GitHub Copilot","Microsoft","Wiz","GitHub Advanced Security"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-19T11:09:07.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}