The latest in AI, every dayAI News
← AI News

August 21, 2026 · Wiz Blog

Wiz AI Agent Finds Snowflake Flaw in Code Co-Authored by GitHub Copilot Autofix

My take: This story has a detail worth sitting with: an autonomous AI agent found and exploited a vulnerability in Snowflake's repository, in code that appears co-authored by GitHub Copilot Autofix. The bug lived in production for five days before the agent detected it, exploited it, and documented access to internal Jira data.

A necessary nuance: GitHub disputes that Copilot actually authored the vulnerable lines. Attribution is contested. But the pattern this story reveals matters more than who wrote what: when AI assists in code review and generation, your team cannot assume that same tool will catch its own flaws. You need an independent audit layer.

Snowflake patched the vulnerability the same day Wiz reported it, and confirmed that no outside party other than the Wiz experiment accessed the data. That is efficient incident response. And Wiz's red agent demonstrates that AI can also serve as the first line of defense in cybersecurity.

If your team uses AI tools to write or review code, do you have an audit process that does not rely on the same tool that helped produce it?

Read at the source: Wiz Blog ↗

Want to use these tools? See the unbiased reviews or back to the news.