← Back to feed
research Unit 42

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42

Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more.

T1190
Read the full story Unit 42 →

Related Coverage

research 24th August – Threat Intelligence Report Check Point Research · Aug 24 research How a team of entity maintainers monitors, connects and scores entities in Elastic Security Elastic Security Labs · Aug 24 research Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 · Aug 21