Autonomous AI exploits raise stakes for vulnerability management | TechTarget
AI agents are autonomously discovering and exploiting software vulnerabilities, prompting CISOs and other security pros to question whether conventional application security methods can keep pace. Even more critical, they need to know which AI-discovered vulnerabilities deserve immediate attention.
The latest high-profile incident started when Wiz's Red Agent, an AI-powered pen-testing tool, discovered a GitHub Actions workflow vulnerability in Snowflake's public repository that previous security checks missed. Without any human intervention, Red Agent developed an exploit and gained access to Snowflake's internal Jira system.
Wiz reported the vulnerability, and Snowflake quickly fixed the flaw, claiming that no one gained unauthorized access.
"Critical vulnerabilities can still be introduced and approved within workflows involving AI coding agents, and can still pass established automated security checks," Gal Nagli, head of threat exposure at Wiz, wrote in a blog.
What makes this incident different
This isn't the first time AI has found a vulnerability,...
Copyright of this story solely belongs to techtarget.com. To see the full text click HERE