Aug 17 2026
Wiz's attack agent exploits a Snowflake repository flaw introduced in a commit co-authored by GitHub Copilot Autofix, extracting a Jira token; GitHub disputes that Copilot wrote the vulnerable lines.
SAFETYINFRA
Original reporting
No source was cited for this one in the issue that logged it. The link above searches for it instead of guessing at a URL.
A June 18th change replaced sanitized input with direct string expansion in a workflow; a crafted issue title could run commands on the runner. Reported and patched June 23rd, disclosed this week.
Named in this event
WizSnowflakeGitHub
Issues that mention Wiz, Snowflake, GitHub
- Daily brief, August 11th 2026
- Daily brief, August 13th 2026
- Daily brief, August 14th 2026
- Daily brief, August 15th 2026
- Daily brief, August 16th 2026
- Daily brief, August 18th 2026
Around the same time