AI Is Going Just Great
← Timeline
·1d agoEmbarrassingMinormicrosoft

Wiz Blamed GitHub Copilot for a Security Flaw a Human Engineer Actually Wrote

Published · curated by AI Is Going Just Great

Source: itpro.com

"Initially the blog implied the vulnerable code flow was generated by AI." — Ami Luttwak, Wiz CTO

Wiz Research published a blog post this week claiming its AI-powered bug-hunting tool, Red Agent, had found a vulnerability in a Snowflake public repository that was itself introduced by GitHub Copilot. The story had a clean narrative: AI finds flaw, AI caused flaw. The problem was that it wasn't quite true. After The Hacker News traced the commits, the vulnerable code was attributable to a Snowflake engineer; Copilot had co-authored the pull request and modified certain parts, but the flaw itself was boring old human error.

Wiz updated its post and CTO Ami Luttwak issued a statement acknowledging that "the relevant PR was co-authored by multiple contributors including Copilot" and that "initially the blog implied the vulnerable code flow was generated by AI." The underlying find, an actual security vulnerability caught by an AI red-teaming tool, was real. The AI-wrote-a-vuln angle was not.