Patch your Jira Service Management Server and Data Center and check for compromise! (CVE-2023-22501)
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Wiz disclosed a GitHub Actions workflow injection in Snowflake's snowflake-connector-net repo that exposed Jira API tokens; Snowflake patched the flaw.
Wiz disclosed a workflow injection flaw in Snowflake's snowflake-connector-net repository, where attacker-controlled GitHub issue fields were expanded directly into a shell run block. Wiz's Red Agent exploited it during authorized security testing, received an out-of-band runner callback and retrieved a Jira API token with read access to engineering, security compliance and bug bounty projects. Snowflake merged a fix on June 23, 2026, rotated the token and said its investigation found no evidence of unauthorized access. No CVE, CVSS score or KEV entry has been assigned for the issue.
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Stratus Security open-sourced Sift, a CLI secrets scanner covering Active Directory, SharePoint, Teams, Slack, Jira, and Confluence, outperforming Snaffler in benchmarks.
Stratus Security released Sift, a free open-source command line tool that hunts passwords, API keys, and sensitive data across local disks, Windows shares, Active Directory, SharePoint, OneDrive, Teams, Slack, Jira, and Confluence. In the firm's benchmarks, Sift scanned 250,000 files in 10.61 seconds versus Snaffler's 25.48 and averaged 92 MiB memory versus Snaffler's 337 MiB. Optional false-positive filtering runs through a local language model via Ollama, and scans write checkpoints so interrupted runs resume. The tool found thousands of credentials in Jira ticket comments that prior pentesting had missed.
Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw in a GitHub Copilot–Assisted PR
Wiz's autonomous Red Agent found and exploited a GitHub Actions injection in a Copilot-assisted PR, reaching Snowflake's internal Jira without human help.
Wiz's Red Agent autonomously discovered a GitHub Actions injection flaw in a GitHub Copilot-assisted pull request, five days after the flaw went live. It exploited the flaw to validate access to sensitive data in Snowflake's internal Jira, bypassing detection by GitHub Advanced Security, and assessed the blast radius without human intervention. The exercise demonstrates agentic AI performing end-to-end offensive security operations against production systems.