Wiz Research has revealed that its autonomous AI security agent, Red Agent, discovered and exploited a critical GitHub Actions vulnerability in Snowflake's infrastructure, ultimately reaching sensitive data inside Snowflake's internal Jira. The flaw lived in the snowflake-connector-net repository and was introduced when PR #1218 was merged on June 18, 2026. Red Agent found and exploited it five days later, all without human intervention.

The concerning part for developers: the vulnerable change was merged with the help of GitHub Copilot, which reviewed the final PR and gave it an all-clear. GitHub Advanced Security also scanned the revision and failed to flag the critical script injection, which allowed an unauthenticated attacker to run arbitrary commands on a GitHub Actions runner by opening an issue with a specially crafted title. Copilot was a co-author of the change and checked the merged code without noticing the vulnerability.

Wiz responsibly disclosed the issue on June 23, and Snowflake remediated it the same day, rotated the affected credential, and confirmed via audit logs that Wiz was the only actor during the exposure window. The case is a sharp reminder that AI-assisted code review is not a substitute for security review. Autonomous AI agents are now writing, reviewing, and attacking code, and the defenders need AI tooling that can keep up.