A security fix written by GitHub’s Copilot Autofix and merged into a Snowflake repository on June 18, 2026 stripped out a sanitized input pattern and left the company’s CI/CD pipeline open to command injection, and five days later, an autonomous AI research agent found the hole, exploited it, and pulled working Jira credentials out of a GitHub Actions runner, Wiz Research disclosed on August 17, 2026. The vulnerability sat in jira_issue.yml, a GitHub Actions workflow in…