Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
A significant security flaw was discovered in Google's Vertex AI SDK that allowed attackers to hijack machine learning model uploads by using a method called "bucket squatting." Palo Alto Networks' Unit 42 found this vulnerability, dubbed "Pickle in the Middle," through Google's bug bounty program, and it could enable attackers to run malicious code within Google's serving infrastructure without needing access to the victim's project. This bug highlights the critical importance of robust security measures in cloud services, especially as machine learning models become more integral to businesses. Thankfully, no instances of exploitation in the wild have been reported, but the potential for misuse is a serious concern.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.