Snowflake GitHub Actions Workflow Flaw Enabled Command Injection and Jira Token Theft
A vulnerability in a GitHub Actions workflow at Snowflake allowed any unauthenticated user to execute arbitrary commands on a runner simply by opening a specially crafted issue in a public repository.
The flaw resided in the snowflakedb/snowflake-connector-net repository. Issue titles and bodies were passed directly into shell commands without proper sanitization, creating a classic command-injection vector. An intended access-control check also failed because it referenced a pull-request property that does not exist in issue events, allowing ordinary users to bypass the restriction.
During authorized testing, an autonomous security agent exploited the weakness and retrieved a Jira API token stored in the workflow’s environment variables. The token provided read access to internal projects covering engineering, security compliance, and bug-bounty programs—information that could support further attack stages.
The vulnerable workflow remained active between 18 and 23 June 2026. Snowflake fixed the code on the same day the report was received and replaced the exposed token the following day. The affected code had been introduced in a pull request that included participation from GitHub Copilot, although the commit history does not prove the AI generated the insecure lines.
Related articles
Apple Releases macOS Tahoe 26.6.2 Fixing 28 Vulnerabilities Including Kernel Flaws
Apple has issued macOS Tahoe 26.6.2, addressing a total of 28 security vulnerabilities tracked under CVE identifiers. The update resolves three kernel-level issues, among them a Use After Free flaw tracked as CVE-2026-65343, an out-of-bounds memory read in CVE-2026-65349, and a memory corruption problem in CVE-2026-65330. Twenty-one of the fixed vulnerabilities affect the WebKit engine, with additional patches applied to Audio, ImageIO, and IOGPUFamily components. The release incorporates fixes that were previously tested in the macOS Golden Gate 27 beta. On the following day, Apple also shipped Safari 26.6.1 for macOS Sonoma and macOS Sequoia, eliminating the same set of 21 WebKit vulnerabilities.
Google Releases Chrome Security Update Fixing 15 Vulnerabilities Including Two Critical Flaws
Google has issued a security update for its Chrome browser that addresses 15 vulnerabilities, two of which are rated critical. The update covers Windows, macOS, and Linux platforms with specific version numbers released on August 18, 2026. Among the fixes are buffer overflow issues in WebGL and Dawn that were reported by Google since mid-July. Thirteen high-severity vulnerabilities were also resolved, including type confusion and calculation errors in the V8 engine, Use After Free flaws in Browser and WebGL, buffer overflows in ANGLE, and information leaks in Skia. Additional problems fixed involve CORS implementation weaknesses, CredentialProvider link handling, USB race conditions, and uninitialized GPU resources. The patches are being rolled out gradually over the coming days and weeks.
The Tale of Active Directory Domain Sabotage: Architect Plants DNS-Killing Task on Departing Branch Controllers
A detailed case study from a former Windows Server 2003 Active Directory environment describes how an architect embedded a monitoring script on branch domain controllers to detect prolonged loss of VPN connectivity to headquarters. The script incremented a hidden registry counter each time the head office IP failed to respond and triggered a net stop dns command once the threshold was exceeded, effectively collapsing the AD domain for the departing branches. The architect later cleaned up traces by reassigning tasks and ownership to the SYSTEM account. A network engineer eventually noticed the repeated DNS service stops, restarted the service multiple times, and eventually contacted the architect. The story illustrates both the critical dependency of Active Directory on DNS and the inherent risk posed by highly privileged administrators who can weaponize that dependency. Two main conclusions are drawn: DNS failure immediately renders an AD domain unusable, and every domain administrator represents the primary threat to domain integrity.
Apple Patches CVE-2026-43760 Screen Sharing Flaw Granting Root Access on macOS
A vulnerability in the macOS Screen Sharing feature allows remote attackers to execute commands with root privileges under specific configurations. Identified as CVE-2026-43760 and tied to the screensharingd service, the flaw affects systems with Screen Sharing or Remote Management enabled alongside the legacy VNC password option. Attackers who know the VNC password can exploit unauthenticated account binding to retrieve protected files such as /etc/sudoers or write policies into /private/etc/sudoers.d. This grants non-privileged accounts passwordless sudo rights. The issue stems from VNC-authenticated connections not being mapped to specific macOS accounts while file-transfer components retain root privileges. Apple addressed the vulnerability in macOS Tahoe 26.6 and macOS Sonoma 14.8.8, both released on July 27, 2026.