Skip to main content

Tag: workflow injection

2 articles

Developer workstation with laptop and terminal, surrounded by notes and whiteboard, in a bright modern office.

Wiz Exposes GitHub Actions Flaw in Snowflake Repository

Researchers at Wiz uncovered a vulnerability in Snowflake's GitHub repository, where a flawed GitHub Actions workflow exposed a sensitive Jira API token, putting internal credentials at risk. This security gap allowed attackers to potentially execute commands using a crafted GitHub issue.

Analyst 207
Developer workstation with code on terminal screen, notes, and coffee cups, surrounded by blurred software team workspace.

AI Coding Assistants Expose Vulnerability Risks

In just five days, an AI-assisted commit introduced a workflow injection bug, and an AI attacker autonomously found and abused it, highlighting the vulnerability risks of relying on AI coding assistants. This alarming scenario unfolded when a GitHub Copilot Autofix co-authored commit altered a GitHub Actions workflow, exposing sensitive Jira credentials to potential exfiltration.

Analyst 207