AI Agent Exploits Vulnerability Missed by GitHub Copilot in Snowflake Repository

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Wiz's autonomous AI agent, Red Agent, discovered and exploited a script injection vulnerability in Snowflake's public GitHub repository, which GitHub Copilot Autofix failed to detect. The flaw enabled unauthorized access to sensitive internal data, highlighting the risks of AI-assisted development and the need for robust oversight in AI-driven cybersecurity.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves AI systems directly in both the discovery and exploitation of a security vulnerability, resulting in unauthorized access to sensitive data, which is a clear harm to property and organizational security. The AI system's role is pivotal, as the vulnerability was autonomously found and exploited by an AI agent, while another AI system failed to detect it. This meets the criteria for an AI Incident because the harm has materialized and is directly linked to the development, use, or malfunction of AI systems.[AI generated]
AI principles
Privacy & data governanceSafety

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Business

Harm types
Human or fundamental rightsEconomic/Property

Business function:
ICT management and information security

AI system task:
Event/anomaly detectionGoal-driven organisation


Articles about this incident or hazard