#ShellInjection
Wiz's autonomous Red Agent found a shell injection flaw in a Snowflake GitHub Actions script, missed by GitHub Copilot, and used it to reach internal Jira credentials.

#Snowflake #GitHubActions #Wiz #ShellInjection #AISecurity
AI Agent Finds GitHub Actions Bug, Reaches Snowflake’s Internal Jira
An AI agent designed to hunt for vulnerabilities independently discovered a flaw within a public Snowflake repository and used it to gain access to the company's internal Jira system. The vulnerability had existed for just five days when discovered, and notably, GitHub Copilot had reviewed the code during that window without flagging the dangerous section. Wiz's Red Agent Uncovers the Flaw…
meterpreter.org
August 19, 2026 at 2:02 PM
Ok, this is a really slick attack. A lot can go wrong with machine learning code, but this is a known problem. This is why we don't call command line executables in web apps.

https://securityaffairs.com/194546/ai/guardfall-flaw-hits-10-of-11-popular-open-source-ai-agents.html

#bash #shellinjection
GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents
GuardFall affects 10 of 11 open-source AI agents, letting attackers bypass command filters through a shell injection weakness.
securityaffairs.com
July 2, 2026 at 3:24 AM