logo

Double Agents in the Cloud: Unit 42 Unmasks Critical AI Vulnerabilities in Google Vertex AI

ID: 93fcb5fa-6701-535c-b716-08a24e3e8c5b

STIX ID: report--93fcb5fa-6701-535c-b716-08a24e3e8c5b

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Unit 42 research identified critical permissioning flaws in Google Vertex AI agents that allow a compromised agent to extract service-agent credentials from the metadata service, gain broad read access to Google Cloud Storage buckets across a consumer project, and access restricted Google-owned Artifact Registry repositories to download private container images. The report also highlights insecure packaging (Python pickle) enabling RCE and persistent backdoors, over-permissive default OAuth scopes and P4SA permissions, and recommends BYOSA and stricter permission and integrity checks to mitigate the risk of AI agents becoming persistent “double agents.”

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.