Skip to main content
SnowflakePartnership

An AI broke Snowflake's code. Then another AI agent exploited it

What happened

Snowflake is collaborating with security firm Wiz to share learnings from a recent vulnerability disclosure with the broader industry.

Source

Article excerpt

Security Don't worry, this one was via a bug bounty program An AI broke Snowflake’s code; then another AI, an attack agent, autonomously found the bug, exploited it, and extracted credentials without human intervention. Luckily, this wasn’t yet another case of rogue AI agents doing evil things. It was a sanctioned bug hunt, conducted through Snowflake’s HackerOne vulnerability disclosure program, and Snowflake fixed the flaw the same day Wiz reported it and rotated the affected credentials the following day. Wiz’s red agent, an AI-powered autonomous attacker designed for offensive security, found the GitHub Actions workflow flaw during a routine scan of public repositories on June 23. The script injection vulnerability existed in snowflakedb/snowflake-connector-net, and it allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title. And it turned out an AI had inadvertently injected the bug into the code five days earlier. GitHub Copilot Autofix, an AI coding assistant, co-authored the commit on June 18, and it introduced a script injection bug in run: blocks by removing the repository’s existing sanitized input pattern and replacing it with direct string expansion in a shell script. “We crafted an issue title that, after template expansion, breaks out of the echo string and...

Keep reading with a free account

The rest of this article, and every signal for Snowflake, is in your free account.

Extracted from this sentence

“We are working together with Wiz to share these learnings with the broader industry to encourage widespread adoption of these security best practices.”

Extracted by Autobound

From the Signal API record
Event
Partnership

What this signalsA new partnership often opens integration and co-selling work.

More partnership signals at other companies

The full record

From the Signal API record

Extraction

Confidence
90%
Detected
Aug 17, 2026
signal_type
news
signal_subtype
partners_with

Use this data

Get every partnership signal for Snowflake and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Snowflake this week?”

  2. Send it to your own tools

    The Signal API returns partnership signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/dc638197-e4aa-55c7-766d-b3e87d8eb52a returns this record as JSON. POST /v1/companies/enrich returns every signal for snowflake.com.

{
  "signal_id": "dc638197-e4aa-55c7-766d-b3e87d8eb52a",
  "signal_type": "news",
  "signal_subtype": "partners_with",
  "detected_at": "2026-08-17T16:36:21+00:00",
  "company": {
    "name": "Snowflake",
    "domain": "snowflake.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/08/17/an-ai-broke-snowflakes-code-then-another-ai-agent-exploited-it/5288666",
    "title": "An AI broke Snowflake's code. Then another AI agent exploited it",
    "excerpt": "Security Don't worry, this one was via a bug bounty program An AI broke Snowflake’s code; then another AI, an attack agent, autonomously found the bug, exploited it, and extracted credentials without human intervention. Luckily, this wasn’t yet another case of rogue AI agents doing evil things . It was a sanctioned bug hunt, conducted through Snowflake’s HackerOne vulnerability disclosure program, and Snowflake fixed the flaw the same day Wiz reported it and rotated the affected credentials the following day. Wiz’s red agent , an AI-powered autonomous attacker designed for offensive security, found the GitHub Actions workflow flaw during a routine scan of public repositories on June 23. The script injection vulnerability existed in snowflakedb/snowflake-connector-net , and it allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title. And it turned out an AI had inadvertently injected the bug into the code five days earlier. GitHub Copilot Autofix, an AI coding assistant, co-authored the commit on June 18, and it introduced a script injection bug in run: blocks by removing the repository’s existing sanitized input pattern and replacing it with direct string expansion in a shell script. “We crafted an issue title that, after template expansion, breaks out of the echo string and...",
    "summary": "Snowflake is collaborating with security firm Wiz to share learnings from a recent vulnerability disclosure with the broader industry.",
    "planning": false,
    "image_url": "https://image.theregister.com/5288720.jpg?imageId=5288720&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 0.9,
    "published_at": "2026-08-17T16:36:21Z",
    "article_sentence": "“We are working together with Wiz to share these learnings with the broader industry to encourage widespread adoption of these security best practices.”",
    "related_company_name": "Wiz",
    "related_company_domain": "wiz.io"
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.