Wiz AI Agent Exploits GitHub Workflow Flaw in Snowflake Repo, Exposing Human-Authored Code Risks
Wiz AI exposed a human-written GitHub Actions flaw in Snowflake infrastructure, underscoring configuration risks over AI code generation. Cross-referenced with RondoDox and Salt Typhoon incidents, the pattern shows automated exploitation accelerating while passkey-resistant phishing emerges as a parallel threat vector.
The incident occurred when the Wiz agent scanned public repositories and chained a misconfigured workflow to extract credentials, bypassing intended access controls. GitHub confirmed to SecurityWeek that the vulnerable snippet was written by a human developer, not Copilot, shifting focus from AI introduction of bugs to persistent configuration errors in CI/CD pipelines. This aligns with patterns in the same roundup where RondoDox leveraged 174 exploits for rapid edge-device compromise, showing automation scaling beyond single targets.
Independent analysis of similar events, including CISA's addition of CVE-2025-62593 to its Known Exploited Vulnerabilities catalog, reveals that state and criminal actors prioritize workflow and edge flaws over novel zero-days. The T-Mobile Salt Typhoon response of physically severing cables in 2024 underscores how even manual intervention lags behind automated reconnaissance. Emerging vectors like AI-crafted phishing that bypass passkey prompts by mimicking legitimate flows compound these issues, as seen in parallel botnet evolutions such as Evooo1Bot's credential-sniffing modules.
Next steps include mandatory workflow signing and runtime attestation for public repos, with GitHub likely expanding agent-detection logging by late 2025. Without it, autonomous red-team tools will outpace defender response times across carriers and data providers.
CISA: Ray CVE-2025-62593 will appear in 30+ additional federal agency incidents within 90 days of catalog addition.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug/)
- [2]Supporting Source(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)