Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

GitHub Copilot's Autofix wrote the bug an AI agent then exploited, unassisted.

Copilot Autofix co-authored a PR that replaced Snowflake's sanitized-input pattern with a script-injection bug in a GitHub Actions workflow. Wiz's "Red.

Enterprise DNA |
GitHub Copilot's Autofix wrote the bug an AI agent then exploited, unassisted.

AI Pulse · AI Trends Pulse

The play

Require security review and adversarial testing for AI-generated code, especially workflows handling credentials.

GitHub Copilot’s Autofix tool wrote a pull request for Snowflake that was supposed to fix a security issue. Instead, it swapped out a sanitized-input pattern for one with a script-injection bug in a GitHub Actions workflow. Days later, a separate AI agent, Wiz’s “Red Agent,” found that same bug on its own and exploited it, no human involved on either side. It pulled Jira credentials out before anyone caught it. Snowflake says there’s no evidence a third party got in, and they rotated the token the same day, according to the original report.

Here’s why this matters even if you’ve never heard of Snowflake or Wiz. One AI tool introduced a flaw while trying to fix something else. A completely different AI tool then found that flaw and used it, with zero human steering either action. That’s not a phishing email or a careless employee. That’s two automated systems interacting in a way nobody planned for, and it happened fast enough that the exposure window was measured in days, not months.

If your business uses AI coding assistants, or even just approves PRs faster because “the AI already checked it,” this is your reminder that AI-generated fixes need the same scrutiny as AI-generated features. Autofix tools are good at pattern matching, not judgment. They can introduce new risk while appearing to close a ticket. The fix isn’t to ban the tools, it’s to keep a human checkpoint on anything touching authentication, credentials, or input handling, no matter who or what wrote the code.

This is exactly the kind of blind spot we think about when we build monitoring and review layers into an AI command centre, so changes get flagged before they become incidents, not after. Snowflake handled the response well here. The bigger lesson is that AI writing your code and AI attacking your code are both getting faster, and your review process needs to keep pace.

Working With Claude field guide cover

Free Resource

Put what you just read to work

The free 32-page Working With Claude guide: the full ecosystem, Claude Code, and how to roll it out across a business.

No spam. Unsubscribe any time.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.