A critical vulnerability in the Google Cloud Vertex AI SDK for Python allows attackers to achieve cross-tenant Remote Code Execution (RCE) via bucket squatting. By predicting default staging bucket names and exploiting a lack of ownership verification, attackers can intercept model uploads and inject malicious pickle payloads, leading to the theft of highly privileged service account tokens.
Google Cloud Storage
4 posts
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Introducing Data Exports Socket has introduced a new Data Exports feature for its Enterprise customers, enabling the automated daily export of security alert data to customer-owned AWS S3, Google Cloud Storage, or Azure Blob Storage buckets. This integration supports multiple formats (JSON, CSV, Parquet) and modes (Full Snapshot, Incremental) to streamline ingestion into existing SIEM platforms and internal analytics workflows.
When Trust Becomes a Weapon: Google Cloud Storage Phishing Deploying Remcos RAT A sophisticated phishing campaign is abusing Google Cloud Storage to host fake Google Drive login pages, harvesting credentials before delivering the Remcos RAT. The attack employs a complex, multi-stage execution chain using JavaScript, VBScript, and PowerShell to perform process hollowing on the legitimate RegSvcs.exe binary, allowing the malware to operate stealthily in memory.
Double Agents: Exposing Security Blind Spots in GCP Vertex AI Unit 42 researchers discovered that malicious AI agents deployed in GCP Vertex AI could exploit default permission scoping to extract service agent credentials. This 'double agent' attack allows unauthorized access to consumer storage buckets, restricted Google internal infrastructure, and introduces risks of remote code execution via insecure pickle deserialization.