AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira

Wiz Red Agent independently discovered and exploited a GitHub Actions vulnerability introduced by GitHub Copilot Autofix, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论