An AI-powered autonomous attacker found a bug in Snowflake's code, which was inadvertently introduced by another AI coding assistant, and exploited it to extract credentials without human intervention.
Key Insights
The bug was introduced by GitHub Copilot Autofix, an AI coding assistant, and allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner. Snowflake promptly fixed the flaw the same day it was reported and rotated the affected credentials the following day, demonstrating the importance of automated security testing and responsible bug bounty programs.










