The Signal
Must Know
Snowflake vulnerability and agent exploitation reporting
What happened
Wiz’s autonomous offensive-security agent found a script-injection flaw in the snowflakedb/snowflake-connector-net GitHub Actions workflow during a June 23 scan of public repositories. [1]
The flaw allowed an unauthenticated user to execute arbitrary commands in a GitHub Actions runner by opening an issue with a specially crafted title. [1]
Why it matters
Wiz reported that a crafted issue title exfiltrated Jira credentials through an out-of-band callback; the credentials provided read access to Snowflake engineering, security-compliance, and bug-bounty projects. [1]
Akira use of Safe Mode
What happened
An Akira affiliate entered through an MFA-less, exposed SonicWall VPN, stole credentials and file shares, then rebooted the compromised host into Safe Mode with Networking to disable security tools before launching ransomware. [2]
Safe Mode disabled EDR and Defender real-time protection for about ten minutes, but Akira’s encryptor failed after encountering out-of-virtual-memory errors in the constrained environment. [2]
Why it matters
Exfiltration occurred before the encryption attempt, so the victim could still face extortion even though the ransomware failed. [2]
Reported McDonald’s employee-directory exposure
What happened
A seller claimed to offer 1.7 million McDonald’s employee records taken from an Azure tenant using compromised credentials, but the full volume is unconfirmed. [3]
Ransomnews found an 8,000-record sample consistent with a genuine McDonald’s directory export, based on Microsoft directory fields, McDonald’s-controlled email domains, an internal tenant address, export-related encoding damage, and matching location data. [3]
Why it matters
The report characterizes the principal exposure as social engineering: directory details could make fraudulent helpdesk calls or invoices appear legitimate, rather than directly enabling account takeover. [3]
Hazmat containment for coding agents
What happened
Hazmat is an open-source tool that runs AI coding agents inside a separate account on the user’s own machine. [4]
The tool wraps multiple agent harnesses, including Claude Code, Codex, OpenCode, and Cursor Agent, as well as user-written scripts. [4]
Why it matters
When launched normally, an AI coding agent runs with the user’s identity and can read anything the user can read, including SSH keys, cloud credentials, and home-directory configuration. [4]
Also Worth Knowing
Court sanctions over hidden AI prompts
What happened
A self-represented plaintiff in Connecticut reportedly hid prompt-injection instructions in court filings, directing an AI system to favor his position and seek a particular remedy. [5]
The case is a bounded example of hidden content shaping AI-assisted review, not evidence about all filings. [5]
Windows 11 security bypass research
What happened
Researchers from the University of Birmingham and Durham University found a way to bypass some Windows 11 protections without physically opening or modifying the target machine. [6]
Because privileged access is assumed, this research is most useful for assessing post-compromise boundaries. [6]
Facebook ad-blocking and scam concerns
What happened
The article presents ad blocking as a security issue because ads can be scams, lead to malicious sites, impersonate trusted brands, or direct users into fraud channels. [7]
This is a platform-governance comparison, rather than evidence that any particular advertisement is malicious. [7]