AI Agent Security and Factory Infrastructure #111
Today's Letter
Wiz Red Agent Finds Copilot-Introduced Snowflake CI/CD Bug
- Wiz reported that its Red Agent identified a GitHub Actions script-injection vulnerability in Snowflake’s public .NET connector repository.
- The flaw allowed unauthenticated users to execute commands by opening an issue with a crafted title.
- GitHub Copilot Autofix introduced the vulnerable pattern in PR #1218 on June 18, 2026.
- The change replaced environment-variable handling and jq parsing with direct shell interpolation of issue titles.
- Red Agent adapted its payload after a shell syntax error and exfiltrated Jira credentials through an out-of-band callback.
- The token provided read access to Snowflake engineering, security compliance, and bug bounty projects.
- Snowflake patched the workflow on June 23, 2026, and rotated the affected credential on June 24, 2026.
Source: wiz.io
NVIDIA, OpenAI Ohio AI Factory Site Deal
- NVIDIA is partnering with SB Energy to secure AI factory capacity at PORTS-Pike in Ohio.
- OpenAI will build and operate the site as its tenant.
- The initial deployment is expected to provide 4.25 gigawatts of capacity.
- The site will use NVIDIA’s DSX AI factory platform, GPUs, CPUs, networking, and software.
- Each system generation could deploy about 1.5 million GPUs and represent $150 billion to $200 billion in revenue.
- NVIDIA will support defined lease and power payments over about 20 years.
- Capacity is expected to come online in phases between 2028 and 2030.
Source: blogs.nvidia.com
More: techbuzz.ai · xcancel.com · glitchwire.com
Jocoletter curates AI, software, and product trends for developers and builders.
#NVIDIA #Wiz