A significant GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. This flaw could have allowed unauthenticated attackers to execute commands on a GitHub-hosted runner and potentially steal internal Jira credentials. The vulnerability was discovered by Wiz Red Agent, an autonomous AI-powered security research tool, just five days after the vulnerable workflow was deployed. Snowflake […]
Read the original article: