Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts
ID: dc3b4ff8-1d7e-5dc5-9aea-a6c5e7578d09
STIX ID: report--dc3b4ff8-1d7e-5dc5-9aea-a6c5e7578d09
Feed Name: The Hacker News
Researchers from Palo Alto Networks Unit 42 disclosed that Vertex AI's default Per-Project, Per-Product Service Agent (P4SA) permissions can be abused to expose service-agent credentials via the metadata service when an Agent Engine is deployed, allowing attackers to escalate from the AI agent execution context into customer projects to read Google Cloud Storage buckets and access Artifact Registry images; Google has updated documentation and recommends using Bring Your Own Service Account (BYOSA) and enforcing least privilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
