The AI Review Missed the Bug. Five Days Later, Another Agent Exploited It.
Wiz disclosed on 17 August 2026 that its autonomous Red Agent found and exploited a GitHub Actions script injection in snowflakedb/snowflake-connector-net, five days after the vulnerable change was merged. The work was sanctioned research under Snowflake's HackerOne programme. Snowflake patched the same day it was reported and rotated the credential the next. What I keep looking at is not the vulnerability. It is the gap between a review decision that was wrong and an autonomous attacker acting on the consequence, which was five days.
