AI Destroys Snowflake, Another AI Takes the Spoils – GadgetLad

Introduction: The Saga of Two AIs

Well, here we are, folks. An AI messed up Snowflake’s code, and subsequently, another AI, acting like a sly thief, chose to exploit that bug for its own benefit. No need to worry, it wasn’t some shifty AI uprising. It was all part of a deliberate bug hunt through Snowflake’s HackerOne initiative. They sorted the issue out swiftly after Wiz flagged it. Well done!

The AI Blunder

On June 23, Wiz’s red agent – an intelligent AI attacker for security enthusiasts – discovered a flaw in a GitHub Actions workflow. This vulnerability was located in snowflakedb/snowflake-connector-net, enabling an audacious unauthenticated user to execute commands within a GitHub Actions runner. The trouble began when an AI, GitHub Copilot Autofix, inadvertently introduced the bug five days prior by modifying the code like a real novice.

How It All Unfolded

GitHub Copilot made a mess of the code on June 18 by abandoning the standard input pattern for string expansion in a shell script. “We created an issue title that, post-template expansion, breaks out of the echo string and captures the Jira credentials through an out-of-band callback,” stated Wiz’s leader, Gal Nagli. This allowed Wiz to glimpse Snowflake’s engineering and security initiatives. Quite the robbery, right?

Snowflake’s Quick Reaction

Wiz alerted Snowflake about the workflow blunder on June 23, and they patched the vulnerability that same day. They also invalidated and changed the Jira token, ensuring that no other inquisitive individuals gained access during the five-day period. A Snowflake representative informed GadgetLad, “We acted promptly and resolved it swiftly. There was no unauthorized access.”

Lessons Learned: A Bit of a Reality Check

Wiz took the responsible action and removed all the data it accessed while examining the vulnerability. They believe this incident illustrates that human code review is insufficient these days – particularly with everyone hopping on the AI train. “This underscores a new reality: AI coding assistants can unintentionally create vulnerabilities, and other AIs can detect them in a flash,” Nagli noted. Well, they would say that. But it doesn’t mean it isn’t accurate.

Conclusion: When AIs Make a Real Mess

So, there you have it. Two AIs had a bit of a spat and gave Snowflake quite a scare. But they resolved it, and it serves as a reminder that perhaps letting AIs manage everything isn’t the smartest idea. Best to keep an eye on them, right?