İçeriğe geç
Analizler
Unharnessed

Bir AI Security Agent Snowflake'i Hackledi. Copilot Story Noise'du.

Wiz Red Agent, Snowflake repo'da GitHub Actions script injection'ı live olduktan beş gün sonra bulup exploit etti, no human involved. Neyi genuinely agentic yapan, ne ordinary automation, permission chain neden authorship row'dan önemli?

Yazan Adam Maguire Wilson4 dk okuma
Bu sayfada

Haziran'da bir AI agent Snowflake internal Jira'ya girdi ve almost everyone'ın lead ettiği part wrong'du. First version GitHub Copilot vulnerable code'u yazdı diyordu, AI poisoning AI tidy parable. Hours sürdü. Wiz disclosure'ı same day corrected, GitHub attribution'ı flatly disputes, correction sonrası daha strange/useful şey kalıyor: autonomous agent live flaw buldu, exploit yazdı, own failed payload debug etti, working credentials çekti end to end, conventional scanners same code'da nothing. Worth your time story bu.

Temel çıkarımlar - Wiz Red Agent, autonomous offensive security agent, public snowflake-connector-net GitHub Actions workflow'da script injection buldu ve Jira token çalmak için exploit etti. Discovery'den credential exfiltration'a no human keyboard. - Flaw 18 June live, 23 June found/exploited/reported HackerOne. Snowflake same day patch, audit logs only Wiz actor. - Initial Copilot wrote bug claim hours içinde walked back. Vulnerable pattern human-authored, Copilot Autofix documented contribution different file, co-author label squash-merge artefact. - GitHub Advanced Security exact vulnerable revision scanned ve missed. Scanner ve agent same code gördü, only one understood. - Genuinely agentic narrow but real: failed exploit diagnose ve rewrite. Rest good automation with language model.

Ne oldu

Timeline Wiz disclosure ve Snowflake response:

  • 18 June 2026. PR #1218 merged snowflakedb/snowflake-connector-net. jira_issue.yml rewrite, issue açınca Jira tickets. Safe env + jq --arg yerine direct issue-title interpolation shell run:.

  • 23 June. Red Agent injectable flag, exploit build/fire, shell syntax error own payload, diagnose/rewrite, second attempt success. Azure-hosted runner callback base64 Jira API service-account token. Same-day HackerOne report.

  • 23 June. Snowflake patch, safe pattern restore.

  • 24 June. Token revoke/rotate; audit logs only Wiz five-day window; PoC data deleted.

  • 17 August. Wiz write-up Gal Nagli, 19:57 UTC update: Copilot co-author merged PR, unclear vulnerable change AI-assisted.

Token internal Jira read access engineering/security compliance/bug bounty. No customer data, connector unaffected.

23 June 2026 autonomous Red Agent GitHub Actions script injection buldu/exploit etti, Jira token exfiltrate etti, flaw live olduktan beş gün sonra ve no human involvement, Wiz disclosure'a göre. Snowflake patch same day, no third-party access.

Bu exploit CI pipeline'ın quietly ne kadar trust tuttuğuna dair temiz bir lesson. One crafted issue title'ın neye kadar reach ettiğini izleyin:

  1. Trigger. issues: opened, any GitHub account. Conditional gate always true, technical coverage.

  2. Injection. TITLE=$(echo '${{ github.event.issue.title }}' | sed ...); template expansion shell before escaping, single quote closes string, rest executes.

  3. Environment. Runner credentials store by design, Jira service token.

  4. Exfiltration. Base64 token out-of-band callback, logs clean.

  5. Prize. Internal Atlassian read access.

Each link ordinary approved infra. Vulnerability composition. Blast radius runner reach. Same agent governance question: agent what is değil, what can touch.

Five legitimate trust layers chained, GitHub expansion before shell escaping, Wiz write-up.

Ne agentic, ne değil

Burada precise olmak istiyorum, çünkü "AI agent hacks Snowflake" two lazy readings davet ediyor: better marketing'li scanner veya Skynet loose. Details ikisini de desteklemiyor.

Ordinary automation + model. Workflow scanning known injection pattern. Static rule plausible.

Genuinely agentic. First payload failed shell syntax. Agent error read, reason, rewrite, second attempt success, token validate, blast radius map. Attempt-observe-correct agentic architecture loop. Fortune 500, unsupervised.

Not agent. Scope/ethics/disclosure humans via HackerOne. Wiz Red Agent March launch, GA July, partly Claude Opus. Capability rentable product.

Agentic core failed exploit self-diagnosis/rewrite, no human, Wiz disclosure.

Copilot Row least interesting

Copilot wrote bug evidence yok. Documented Autofix contribution jira_close.yml, different file; vulnerable commit human engineer; co-author label squash merge. GitHub says neither wrote/reviewed lines. Wiz corrected.

But Advanced Security scanned vulnerable final revision and missed, undisputed. Real AI-review limitation story. CSO attribution complexity.

Wiz corrected authorship implication; GitHub human author diyor. Scanner miss undisputed, Wiz update, CSO.

Şimdi ne yapmalı

GitHub Actions içinde secrets çalıştırıyorsanız bu hafta şunları yapın:

  1. ${{ github.event.* }} inside run: grep. Untrusted title/comment direct shell no. env: + quoting veya jq --arg.

  2. Runner credential store. Minimum scopes, OIDC, untrusted triggers (issues, pull_request_target, comments) internet-facing.

  3. AI review last line değil. Independent layered checks.

  4. Five days slow. Dwell assumptions update, same-day credential rotation.

FAQ

Copilot vulnerability yazdı mı?

No current evidence. Co-author artefact. Scanner missed true.

Wiz agent Jira'ya nasıl girdi?

Crafted issue title -> arbitrary runner commands -> Jira token -> out-of-band exfil -> internal read.

Real attack mı?

Sanctioned HackerOne, only Wiz actor, no customer data.

AI security agents anlamı?

Offensive ahead defensive. Agent-speed discovery baseline.

Sonuç

Copilot drama çıkar: expensive scanner code'u cleared, autonomous agent same code'u weaponise etti ve own mistakes fixed. Five-day merge-to-machine exploit gap matters. Offensive agents product, no weekends. Attribution forgotten, capability remains.

Pipelines içinde autonomy level çalışıyorsanız clients ile regular conversation. İletişim.

Kaynaklar

  • Wiz Research (Gal Nagli), "Wiz Red Agent Finds Its Way Into Snowflake's Internal Jira Through a Flaw in a GitHub Copilot-Assisted PR": https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug (yayımlanma 2026-08-17, güncelleme 2026-08-17 19:57 UTC, erişim 2026-08-29)

  • Wiz, "Introducing the Wiz Red Agent - AI-Powered Attacker": https://www.wiz.io/blog/introducing-the-wiz-red-agent (yayımlanma 2026-03-23, erişim 2026-08-29)

  • Cybersecurity News, "AI Agent Hacks Snowflake GitHub Workflow": https://cybersecuritynews.com/ai-agent-hacks-snowflake-github-workflow/ (yayımlanma 2026-08-20, erişim 2026-08-29)

  • CSO Online, "Snowflake flaw slips past AI checks, gets exploited by another AI": https://www.csoonline.com/article/4211501/snowflake-flaw-slips-past-ai-checks-gets-exploited-by-another-ai.html (yayımlanma 2026-08-19, erişim 2026-08-29)

  • Infosecurity Magazine, "Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw": https://www.infosecurity-magazine.com/news/wiz-ai-agent-finds-snowflake/ (yayımlanma 2026-08-18, erişim 2026-08-29)

  • daily.dev (from The Next Web), "GitHub disputes Wiz's claim that Copilot Autofix wrote a Snowflake flaw": https://daily.dev/posts/github-disputes-wiz-s-claim-that-copilot-autofix-wrote-a-snowflake-flaw-ybruxnh95 (yayımlanma 2026-08-18, erişim 2026-08-29)

  • snowflakedb/snowflake-connector-net repository: https://github.com/snowflakedb/snowflake-connector-net (erişim 2026-08-29)

Okumaya devam et

Agent Field Notes

Bir sonraki sayıyı alın.

Ajan harness’ları, çalışma zamanı ortamları, güvenlik ve yönetişim; bu sistemleri işletmek zorunda olanlar için açıklanıyor.

Buna benzer bir kararla mı karşı karşıyasınız?

Aracı sistemleri hakkında önemli kararlar alan ekipler için mimari incelemeler, yönetişim değerlendirmeleri ve sürümü sabitlenmiş çerçeve karşılaştırmaları yürütüyoruz.

Yazar hakkında

Adam Maguire Wilson

Kurucu ve yapay zekâ ajan sistemleri bağımsız danışmanı.

adam.mw