unit42.paloaltonetworks.com 6/16/2026, 10:46:45 AM · external

Vertex AI SDK bug enables model hijack via bucket squatting

Vertex AI SDK bug enables model hijack via bucket squatting
CyberSIXT Evidence Panel Source marked as original reporting

THE Palo Alto Networks report discusses a vulnerability in the Google Cloud Vertex AI SDK for Python, which potentially allows attackers to hijack and poison model uploads via a technique known as 'bucket squatting.' This exploit enables remote code execution (RCE) without the attacker needing access to the victim's project. Key details include:

View full article

Article by CyberSIXT