An AI broke Snowflake's code. Then another AI agent exploited it

https://image.theregister.com/5288720.jpg?imageId=5288720&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Don't worry, this one was via a bug bounty program

An AI broke Snowflake’s code; then another AI, an attack agent, autonomously found the bug, exploited it, and extracted credentials without human intervention.

Luckily, this wasn’t yet anothercase of rogue AI agentsdoing evil things. It was a sanctioned bug hunt, conducted through Snowflake’s HackerOne vulnerability disclosure program, and Snowflake fixed the flaw the same day Wiz reported it and rotated the affected credentials the following day.

Wiz’s red agent, an AI-powered autonomous attacker designed for offensive security, found the GitHub Actions workflow flaw during a routine scan of public repositories on June 23. The script injection vulnerability existed in snowflakedb/snowflake-connector-net, and it allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title.

And it turned out an AI had inadvertently injected the...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more