< ciso
brief />
Tag Banner

All news with #snowflake tag

26 articles

Wiz AI Agent Finds Critical Script Injection in Snowflake

πŸ”Ž Security researchers at Wiz, part of Google Cloud, discovered a critical script injection vulnerability in Snowflake’s public GitHub repository that GitHub Advanced Security missed. The issue, found by Wiz Research’s autonomous Red Agent on June 23, allowed unauthenticated command execution in a GitHub Actions runner via a crafted issue title. Snowflake patched the workflow and rotated the Jira token after being notified via HackerOne, reporting no evidence of unauthorized access.
read more β†’

Snowflake GitHub Actions workflow injection exposed Jira token

πŸ”’ Researchers at Wiz disclosed a GitHub Actions workflow injection in Snowflake's snowflakedb/snowflake-connector-net repo that allowed attacker-controlled issue fields to be expanded into a shell run: block, exposing JIRA_BASE_URL, JIRA_USER_EMAIL, and JIRA_API_TOKEN. The vulnerability stemmed from unsafe expression expansion in .github/workflows/jira_issue.yml and incorrect event property checks, which let a crafted public issue reach the job. Snowflake patched the workflow the same day Wiz reported it and rotated the exposed Jira token; no evidence of unauthorized access or affected releases was found.
read more β†’

Snowflake attacker pleads guilty in mass data hacks

πŸ”’ A Canadian hacker has pleaded guilty to participating in a group that compromised logins and breached a US cloud data warehouse, impacting 165 organizations and resulting in theft of customer records and multimillion-dollar extortion. Identified as Connor Riley Moucka, he worked with two co-conspirators and is linked to intrusions affecting companies such as AT&T, Ticketmaster and Neiman Marcus. The coordinated investigation involved the FBI and international law enforcement partners and led to guilty pleas and arrests tied to the Snowflake-focused campaign.
read more β†’

Canadian Hacker Pleads Guilty in Snowflake Extortion Case

πŸ›‘οΈ Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and conspiracy for hacking and extorting more than 165 Snowflake customers and stealing AT&T call and text metadata for over 100 million users. Authorities say the conspirators used stolen credentials where multi-factor authentication was not enforced, exfiltrated terabytes of sensitive data, and extorted victims for ransom. Moucka admitted to threatening officials and security researchers and faces significant prison time at his October sentencing.
read more β†’

Snowflake breach actor pleads guilty in US court

πŸ”’ Connor Riley Moucka pleaded guilty in Seattle federal court to charges including computer fraud, wire fraud and aggravated identity theft for his role in the 2024 Snowflake customer account intrusions that affected at least 165 organizations and exposed data tied to over 100 million people. Prosecutors say attackers used old credentials harvested by infostealer malware and exploited accounts with MFA disabled, resulting in more than $9.5 million in direct victim losses and at least $495,000 personally taken by Moucka.
read more β†’

AWS adds autonomous agents and cross-data analytics

πŸ€– Amazon Quick receives major updates including autonomous agents, multi-dataset analytics, and a redesigned activity feed. Quick connects to common business apps and learns workflows to automate recurring tasks and reduce manual notifications. The multi-dataset analytics lets users query across sources like Snowflake and relational databases using natural language while inheriting semantics from catalogs such as AWS Glue and Databricks Unity Catalog. The updated activity feed provides a conversational, personalized workspace for approvals, messaging, and sharing Quick applications externally.
read more β†’

Amazon Quick expands integrations with 16 new connectors

πŸ”— Amazon Quick now connects to 16 additional tools including Adobe, Figma, WhatsApp, Snowflake, and Smartsheet, enabling teams to act on insights without switching context. The new connectors span productivity, design, analytics, financial intelligence, commerce, and communication, so teams can build cross-tool workflows inside Quick. Integrations are available in all AWS Regions where Amazon Quick is offered.
read more β†’

AWS Secrets Manager adds Datadog and Snowflake support

πŸ” AWS Secrets Manager now supports managed external secrets for Datadog vended keys and Snowflake Programmatic Access Tokens, enabling automatic rotation of third-party credentials directly within Secrets Manager. The update covers Datadog API keys, Application keys, and admin credential pairs for service accounts. For Snowflake, Secrets Manager can rotate Programmatic Access Tokens using Snowflake's native authentication and offers a configurable grace period to minimize disruption. These additions join existing integrations such as BigID, Confluent Cloud, MongoDB Atlas, and Salesforce and are available in all Regions where managed external secrets is supported.
read more β†’

Zara Data Breach Exposes 197,000 Customers' Records

πŸ”’ A ShinyHunters campaign has compromised data for over 197,000 Zara customers, according to HaveIBeenPwned. Stolen items include unique email addresses, product SKUs, order IDs and support ticket data after stolen authentication tokens from analytics provider Anodot were used to access BigQuery and Snowflake instances; the group leaked a claimed 140GB trove. Inditex says no names, passwords or payment details were affected and operations remained unaffected. Other reported victims include Vimeo, Rockstar Games and McGraw Hill.
read more β†’

Amazon Athena Adds Managed Connectors for 12 Sources

πŸ”— Amazon Athena now provides managed connectors for 12 external data sources, including DynamoDB, PostgreSQL, MySQL, and Snowflake, enabling queries against data outside Amazon S3 without deploying connector infrastructure. Athena creates and manages AWS Glue Data Catalog federated connectors on your behalf and registers each source as a federated catalog. You can query those sources alongside S3 data and optionally apply fine‑grained access controls through AWS Lake Formation. Federated queries are available in all standard AWS Regions except AWS GovCloud (US) and China Regions.
read more β†’

AWS Glue Adds OAuth 2.0 Support for Snowflake Connectivity

πŸ”’ AWS Glue now supports OAuth 2.0 for native Snowflake connectivity, allowing customers to read from and write to Snowflake without sharing persistent user credentials. This token-based authorization uses temporary access tokens to eliminate credential management, enabling granular permissions and improved auditability. The built-in AWS Glue Snowflake connector with OAuth is available in all AWS commercial regions, simplifying secure data integration.
read more β†’

Rockstar Games analytics data leaked after Anodot breach

πŸ”“ A data set allegedly belonging to Rockstar Games was published by the ShinyHunters extortion group after they say authentication tokens were stolen from Anodot and used to access connected Snowflake accounts. The leak reportedly contains more than 78.6 million records of internal analytics β€” including in‑game revenue, purchase metrics, player behavior, and game economy data for GTA Online and Red Dead Online β€” plus Zendesk support analytics. Rockstar said only a limited amount of non‑material company information was accessed and that the incident does not affect players.
read more β†’

Snowflake Customers Targeted After SaaS Integrator Breach

πŸ” Over a dozen companies experienced data theft after attackers used stolen authentication tokens from a breached SaaS integrator to access cloud accounts. The majority of observed incidents targeted Snowflake, which reported "unusual activity" and said a small number of customer accounts were impacted. Snowflake emphasized that its systems were not compromised and that it locked down potentially affected accounts and notified customers. BleepingComputer sources point to an alleged breach at Anodot, and the extortion gang ShinyHunters claims responsibility.
read more β†’

Spanner Columnar Engine Preview: Serving Iceberg Lakehouses

πŸš€ The preview of the Spanner columnar engine enables low-latency serving of Apache Iceberg lakehouse data with Spanner’s horizontal scale and strong consistency. It adds a columnar storage layer and vectorized execution to accelerate analytical scans β€” Google cites up to 200Γ— faster scans β€” while isolating heavy analytical queries from transactional workloads. The feature supports on-demand columnar conversion, automatic query routing, and reverse ETL integrations with BigQuery, Databricks, Snowflake and Oracle to make curated analytical data available for real-time applications.
read more β†’

AWS Clean Rooms Adds Parameters to PySpark Templates

🧩 AWS Clean Rooms now supports parameters in PySpark analysis templates, allowing template authors to define input values that collaborators supply at job submission time without editing the template code. When a collaborator is approved to run an analysis, they submit parameter values directly to the PySpark job, enabling reusable templates and faster iteration. This feature lets partners vary time windows, geographic regions, and other inputs dynamically to adapt analyses. It supports collaboration across companies on AWS or Snowflake and helps accelerate time-to-insights for use cases like advertising attribution.
read more β†’

Back Market Migrates to Google Data Cloud, Cuts Costs

πŸ” Back Market migrated its data and core tech stack from AWS-based Snowflake and Databricks to Google Cloud, consolidating all historical and operational data in BigQuery. The team executed a two-week proof of concept and a live double-run migration that kept production on Databricks while writing to cloned BigQuery tables until outputs matched. They replaced AWS DMS with Datastream, implemented hourly batching to control small-file costs, and completed critical switchover in six months. The move halved data processing times, cut CDC costs by 90%, reduced technical debt, and improved observability, governance, and developer productivity.
read more β†’

AWS Secrets Manager Introduces Managed External Secrets

πŸ” AWS Secrets Manager now supports managed external secrets, a new secret type that standardizes storage and enables automated rotation for third-party application credentials such as Salesforce, Snowflake, and BigID. The feature separates rotation metadata from secret values and integrates directly with providers to remove the need for custom rotation functions. It leverages existing IAM, CloudWatch, CloudTrail, GuardDuty, and KMS controls and follows standard Secrets Manager pricing with no additional charge.
read more β†’

AWS Secrets Manager: Managed External Secrets Launch

πŸ” AWS Secrets Manager introduces managed external secrets, a default-enabled feature that automates rotation for third-party SaaS credentials using provider-supported rotation strategies. The service removes the need to build and maintain rotation Lambda functions by enforcing a vendor-prescribed secret format and offering multiple rotation approaches. An onboarding guide enables any SaaS provider to join as a partner and publish prescriptive rotation guidance. At launch, the feature lists Salesforce, BigID, and Snowflake, and is available in all Regions where Secrets Manager operates.
read more β†’

Microsoft Databases and Fabric: Unified AI Data Estate

🧠 Microsoft details a broad expansion of its database portfolio and deeper integration with Microsoft Fabric to simplify data architectures and accelerate AI. Key launches include general availability of SQL Server 2025, GA of Azure DocumentDB (MongoDB-compatible), the preview of Azure HorizonDB, and Fabric-hosted SaaS databases for SQL and Cosmos DB. OneLake mirroring, Fabric IQ semantic modeling, expanded agent capabilities, and partner integrations (SAP, Salesforce, Databricks, Snowflake, dbt) are positioned to deliver zero-ETL analytics and operational AI at scale.
read more β†’

Amazon Quick Suite: Agentic AI Workspace for Business

πŸ€– Amazon Quick Suite is now generally available as an agentic, AI-powered workspace that retrieves insights across the public internet and your enterprise data stores β€” including Slack, Salesforce, Snowflake, databases, and other documents β€” and moves instantly from answers to actions. Quick Suite can execute or trigger tasks in popular applications like Salesforce, Jira, and ServiceNow, and automate workflows from RFP responses to invoice processing and account reconciliation. AWS highlights customer privacy β€” queries and data are not used to train models β€” and administrators can enable and tailor the experience quickly; new customers receive a 30-day trial for up to 25 users.
read more β†’