Lewati ke konten
Analisis
Unharnessed

AI Security Agent Membobol Snowflake. Cerita Copilot Itu Noise.

Red Agent Wiz menemukan dan mengeksploitasi GitHub Actions script injection di repo Snowflake lima hari setelah live, tanpa human involvement. Mana yang benar-benar agentic, mana ordinary automation, dan mengapa permission chain lebih penting daripada authorship row.

Oleh Adam Maguire WilsonBaca 5 mnt
Di halaman ini

AI agent masuk ke internal Jira Snowflake pada Juni, dan bagian yang hampir semua orang jadikan headline adalah bagian yang salah. Versi pertama bilang GitHub Copilot menulis vulnerable code, parabola rapi tentang AI poisoning AI. Bertahan beberapa jam. Wiz mengoreksi disclosure sendiri hari yang sama, GitHub tegas membantah attribution, dan yang tersisa lebih aneh sekaligus berguna: autonomous agent menemukan live flaw, menulis exploit, debugged own failed payload, dan menarik working credentials end to end, sementara scanner konvensional pada same code tidak melihat apa-apa. Itu cerita sebenarnya.

Poin utama - Wiz Red Agent, autonomous offensive security agent, menemukan script injection di GitHub Actions workflow repo publik snowflake-connector-net dan mengeksploitasi untuk mencuri Jira token. Tidak ada human menyentuh keyboard antara discovery dan credential exfiltration. - Flaw live 18 Juni 2026, ditemukan/exploited/reported 23 Juni melalui HackerOne. Snowflake patch same day, audit logs menunjukkan Wiz satu-satunya actor. - Initial claim Copilot wrote bug ditarik dalam beberapa jam. Vulnerable pattern human-authored; Copilot Autofix documented contribution different file; co-author label squash-merge artefact. - GitHub Advanced Security memindai exact vulnerable revision dan melewatkannya. Scanner dan agent melihat same code, hanya satu memahami. - Genuinely agentic part narrow tapi real: diagnosis failed exploit dan rewrite. Sisanya good automation dengan language model.

Apa yang terjadi

Timeline dari Wiz disclosure dan Snowflake response:

  • 18 Juni 2026. PR #1218 merged ke snowflakedb/snowflake-connector-net, public .NET connector repo. jira_issue.yml rewrite untuk auto-create Jira tickets saat GitHub issue dibuka. Safe env + jq --arg diganti direct title interpolation dalam shell run:.

  • 23 Juni. Red Agent flags injectable di bawah HackerOne, membuat exploit, first attempt shell syntax error, mendiagnosis, menulis ulang, sukses second attempt. Azure-hosted runner callback ke Wiz dengan base64 Jira API token service account. Report same day.

  • 23 Juni. Snowflake patch, restore safe pattern.

  • 24 Juni. Token revoked/rotated. Audit logs hanya Wiz dalam five-day exposure. PoC data deleted.

  • 17 Agustus. Wiz publish write-up Gal Nagli, update 19:57 UTC untuk clarify Copilot co-author merged PR, tetapi unclear vulnerable change AI-assisted.

Token punya read access ke internal Jira engineering, security compliance, bug bounty. No customer data, shipped connector unaffected.

23 Juni 2026, Red Agent autonomous Wiz menemukan/exploit script injection di GitHub Actions snowflake-connector-net dan exfiltrate Jira token dengan internal read access, lima hari setelah flaw live dan tanpa human involvement, menurut Wiz Research disclosure. Snowflake patch same day dan logs tidak menunjukkan third-party access.

Exploit ini adalah pelajaran rapi tentang seberapa banyak trust yang diam-diam dipegang CI pipeline. Ikuti apa yang bisa dijangkau satu crafted issue title:

  1. Trigger. issues: opened, any GitHub account bisa trigger. Conditional gate selalu true, menurut technical coverage.

  2. Injection. TITLE=$(echo '${{ github.event.issue.title }}' | sed ...); GitHub template expansion sebelum shell escaping, single quote menutup string, sisa title executes shell.

  3. Environment. Runner penuh credentials, termasuk Jira API token untuk service account.

  4. Exfiltration. Token base64 via out-of-band callback, tidak muncul suspicious logs.

  5. Prize. Internal Atlassian read access engineering/security/bounty.

Semua link ordinary approved infrastructure. Vulnerability adalah composition. Blast radius workflow adalah apa pun yang runner dapat reach. Same principle agent governance: bukan apa agent itu, tetapi apa yang dapat disentuh.

Lima legitimate trust layers chained; template expansion before escaping membuat sanitisation terlambat, menurut Wiz write-up.

Apa yang agentic dan tidak

Saya ingin precise di sini, karena "AI agent hacks Snowflake" mengundang dua lazy reading: hanya scanner dengan marketing lebih bagus, atau Skynet sudah lepas. Detail tidak mendukung keduanya.

Ordinary automation dengan model. Crawl/flag vulnerability class yang bisa static-rule detect.

Genuinely agentic. First payload gagal dengan bash syntax error, agent membaca error, diagnosis malformed payload, rewrite, success second attempt, validate token dan blast radius. Attempt-observe-correct adalah loop agentic architecture. Offensive Fortune 500 unsupervised, notable.

Bukan agent. Scope/ethics/disclosure human authorised via HackerOne. Wiz launched Red Agent Maret, GA late July, partly Claude Opus. Capability sekarang rentable product.

Agentic core adalah exploit loop dengan self-diagnosis dan rewrite tanpa human help, menurut Wiz disclosure.

Copilot Row paling tidak menarik

Copilot did not write flaw berdasarkan current evidence. Documented contribution different file jira_close.yml; vulnerable commit attributed human engineer; co-author label squash merge artefact. GitHub says neither wrote nor reviewed vulnerable lines. Wiz corrected.

Tetapi Advanced Security scanned final vulnerable revision dan missed injection, tidak diperdebatkan. Jadi story valid adalah limitation AI-assisted review, bukan AI authored bug. CSO mengangkat complexity attribution ketika multiple agents run.

Wiz corrected authorship implication; GitHub says human engineer. Undisputed scanner miss, menurut updated post dan CSO.

Apa yang dilakukan sekarang

Jika Anda menjalankan GitHub Actions dengan secrets di dalamnya, lakukan ini minggu ini:

  1. Grep ${{ github.event.* }} dalam run: blocks. Untrusted titles/comments/branches jangan direct shell interpolate. Gunakan env: atau jq --arg.

  2. Runner adalah credential stores. Min scopes, short-lived OIDC, untrusted triggers (issues, pull_request_target, comments) = internet-facing.

  3. AI review bukan last line. Layer independent checks.

  4. Five days sudah lambat. Update dwell assumptions, same-day credential rotation.

FAQ

Copilot menulis vulnerability?

Tidak menurut evidence. Co-author artefact, different file. Scanner miss adalah true.

Bagaimana agent masuk Jira?

Crafted issue title -> arbitrary runner commands -> Jira token -> out-of-band exfil -> internal read.

Real attack?

Sanctioned HackerOne, Wiz only actor, no customer data.

Arti bagi AI security agents?

Offensive agents ahead. Agent-speed discovery jadi baseline.

Kesimpulan

Hilangkan Copilot drama: scanner mahal cleared, autonomous agent weaponised same code dan fixed own mistakes. Five-day merge-to-machine exploit gap adalah angka yang matters. Offensive agents sudah product. Attribution akan hilang, capability tetap.

Jika menentukan autonomy security agents dalam pipelines, ini percakapan rutin dengan clients. Hubungi saya.

Sumber

  • Wiz Research (Gal Nagli), "Wiz Red Agent Finds Its Way Into Snowflake's Internal Jira Through a Flaw in a GitHub Copilot-Assisted PR": https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug (diterbitkan 2026-08-17, diperbarui 2026-08-17 19:57 UTC, diakses 2026-08-29)

  • Wiz, "Introducing the Wiz Red Agent - AI-Powered Attacker": https://www.wiz.io/blog/introducing-the-wiz-red-agent (diterbitkan 2026-03-23, diakses 2026-08-29)

  • Cybersecurity News, "AI Agent Hacks Snowflake GitHub Workflow": https://cybersecuritynews.com/ai-agent-hacks-snowflake-github-workflow/ (diterbitkan 2026-08-20, diakses 2026-08-29)

  • CSO Online, "Snowflake flaw slips past AI checks, gets exploited by another AI": https://www.csoonline.com/article/4211501/snowflake-flaw-slips-past-ai-checks-gets-exploited-by-another-ai.html (diterbitkan 2026-08-19, diakses 2026-08-29)

  • Infosecurity Magazine, "Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw": https://www.infosecurity-magazine.com/news/wiz-ai-agent-finds-snowflake/ (diterbitkan 2026-08-18, diakses 2026-08-29)

  • daily.dev (from The Next Web), "GitHub disputes Wiz's claim that Copilot Autofix wrote a Snowflake flaw": https://daily.dev/posts/github-disputes-wiz-s-claim-that-copilot-autofix-wrote-a-snowflake-flaw-ybruxnh95 (diterbitkan 2026-08-18, diakses 2026-08-29)

  • snowflakedb/snowflake-connector-net repository: https://github.com/snowflakedb/snowflake-connector-net (diakses 2026-08-29)

Lanjutkan membaca

Agent Field Notes

Dapatkan edisi berikutnya.

Harness agen, runtime, keamanan, dan tata kelola, dijelaskan untuk orang-orang yang harus mengoperasikan sistem ini.

Menghadapi keputusan seperti ini?

Kami menjalankan tinjauan arsitektur, penilaian tata kelola, dan evaluasi framework dengan versi terkunci untuk tim yang mengambil keputusan penting tentang sistem agen.

Tentang penulis

Adam Maguire Wilson

Pendiri dan penasihat independen untuk sistem agen AI.

adam.mw