AI Agent Security and Factory Infrastructure #111

Today's Letter

  1. Wiz Red Agent Finds Copilot-Introduced Snowflake CI/CD Bug
  2. NVIDIA, OpenAI Ohio AI Factory Site Deal

Wiz Red Agent Finds Copilot-Introduced Snowflake CI/CD Bug

Wiz Red Agent Finds Copilot-Introduced Snowflake CI/CD Bug
  • Wiz reported that its Red Agent identified a GitHub Actions script-injection vulnerability in Snowflake’s public .NET connector repository.
  • The flaw allowed unauthenticated users to execute commands by opening an issue with a crafted title.
  • GitHub Copilot Autofix introduced the vulnerable pattern in PR #1218 on June 18, 2026.
  • The change replaced environment-variable handling and jq parsing with direct shell interpolation of issue titles.
  • Red Agent adapted its payload after a shell syntax error and exfiltrated Jira credentials through an out-of-band callback.
  • The token provided read access to Snowflake engineering, security compliance, and bug bounty projects.
  • Snowflake patched the workflow on June 23, 2026, and rotated the affected credential on June 24, 2026.

Source: wiz.io


NVIDIA, OpenAI Ohio AI Factory Site Deal

  • NVIDIA is partnering with SB Energy to secure AI factory capacity at PORTS-Pike in Ohio.
  • OpenAI will build and operate the site as its tenant.
  • The initial deployment is expected to provide 4.25 gigawatts of capacity.
  • The site will use NVIDIA’s DSX AI factory platform, GPUs, CPUs, networking, and software.
  • Each system generation could deploy about 1.5 million GPUs and represent $150 billion to $200 billion in revenue.
  • NVIDIA will support defined lease and power payments over about 20 years.
  • Capacity is expected to come online in phases between 2028 and 2030.

Source: blogs.nvidia.com
More: techbuzz.ai · xcancel.com · glitchwire.com


Jocoletter curates AI, software, and product trends for developers and builders.

#NVIDIA #Wiz

Subscribe to Jocoletter

Read more