Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Trending AI News

AI Agent Found the Bug That Copilot Helped Create

Wiz Red Agent found a GitHub Actions injection in Snowflake's repo linked to a Copilot Autofix commit. What this means for businesses using AI coding tools.

Enterprise DNA | | via The Hacker News
AI Agent Found the Bug That Copilot Helped Create

An AI security agent found a critical vulnerability in Snowflake’s GitHub repository — one that appears to have been introduced by a GitHub Copilot Autofix commit. The story is a perfect illustration of where enterprise AI sits right now: capable, fast, occasionally dangerous, and increasingly indispensable for catching its own mistakes.

Here’s what happened, why it matters, and what businesses running AI tools should take away from it.

What Happened

Snowflake’s open-source connector repository contained a GitHub Actions workflow that automatically created Jira tickets whenever a new GitHub issue was opened. In June 2026, a change was made to that workflow that opened a shell injection hole. An attacker could exploit it simply by opening a GitHub issue with a specially crafted title — the repository would then execute arbitrary commands inside a GitHub Actions runner, potentially exposing internal infrastructure.

Wiz Red Agent, Wiz’s autonomous AI security agent, independently discovered and exploited the vulnerability five days after it went live. The agent validated that it could access Snowflake’s internal Jira, assessed the blast radius, and documented the finding — all without human intervention. Wiz reported the bug to Snowflake on June 23, 2026. Snowflake patched it the same day.

The Copilot Controversy

The commit that introduced the vulnerable change lists “Copilot Autofix powered by AI” among its co-authors. That attribution set off a debate about AI-assisted coding and accountability.

GitHub pushed back. The company says an internal review shows the co-authored Copilot commit changed a different file entirely, while the actual unsafe refactor sits in a separate commit attributed to a named Snowflake engineer. In GitHub’s telling, the attribution is misleading — Copilot contributed code, but not the code that caused the vulnerability.

The specific attribution dispute may never be fully resolved. But the broader pattern is real: AI coding assistants can and do contribute to codebases in ways that introduce security issues, and the current tooling doesn’t make it easy to trace exactly what AI wrote versus what a human did.

What Wiz Red Agent Actually Demonstrated

Set aside the Copilot attribution question for a moment. The more remarkable part of the story is what Wiz Red Agent did:

  • Identified a live, exploitable vulnerability in a major enterprise software company’s public repo
  • Exploited it to confirm access to sensitive internal systems
  • Scoped the potential damage
  • Did all of this autonomously, within days of the vulnerability going live

This is agentic AI operating exactly as advertised. An AI agent running continuously against publicly accessible attack surfaces, finding real vulnerabilities faster than human security teams could, and doing it without being explicitly prompted to check that specific repo on that specific day.

That capability cuts both ways. Wiz used it defensibly and reported the finding. Someone else could have used the same approach offensively.

What This Means for Business

If you’re running AI coding tools across your engineering team, this story contains several practical signals worth paying attention to.

AI-assisted code still needs review. Copilot, and tools like it, accelerate development significantly. But they don’t eliminate the need for code review — they may actually increase it. AI-generated or AI-modified code can introduce issues that look plausible on the surface and pass automated checks, particularly in configuration files and CI/CD workflows where the blast radius of a small mistake is large.

Autonomous AI agents are now doing security work. The same class of tool you’re deploying to automate customer service or data pipelines is being deployed by security teams to probe production systems continuously. If your infrastructure has exploitable gaps, the probability that an AI agent finds them — whether yours or someone else’s — is rising fast.

Attribution in AI-assisted work is genuinely hard. The GitHub dispute over Copilot’s role in the Snowflake flaw illustrates a problem that will only grow. As more code is co-authored by AI, tracing what AI contributed versus what a human wrote becomes complex. Businesses need policies and tooling for this now, not after an incident.

The patch window is shrinking. This vulnerability was live for five days before an AI found it. That’s not much time. For businesses running public-facing repositories, the expectation should increasingly be that any exploitable flaw will be found and potentially exploited within days of introduction.

The Bigger Picture

This story isn’t a reason to distrust AI coding tools or AI security agents. It’s a reason to use both more deliberately.

AI coding assistants like Copilot raise engineering productivity. AI security agents like Wiz Red Agent raise the bar for what continuous security monitoring looks like. The organizations that will get the most from both are the ones that build proper review gates, maintain clear accountability chains for AI-contributed code, and treat agentic security tooling as a permanent part of their infrastructure — not a one-time audit.

The gap between what AI can do and what most business processes are built to handle is closing. The Snowflake incident is a preview of that gap being crossed.


For businesses building or deploying AI agents as part of their operations, the question isn’t whether AI-introduced risks are real. It’s whether your governance keeps pace with your adoption. Enterprise DNA’s Omni Advisory service helps leadership teams build AI strategies that account for both the upside and the operational risks. Book a session with the Omni Advisory team to map your own AI governance gaps.

Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

No spam. Unsubscribe any time.