← Back to feed
research Unit 42

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42 •

Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more.

T1190
Read the full story Unit 42 →

Related Coverage

research MATCHBOIL: New tricks, same old evil intentions ESET Research · Oct 8 research Introducing AlertZero: Inbox zero for your alert queue Elastic Security Labs · Oct 8 research Japan Adopts Proactive Cyber Defense Strategy Recorded Future · Oct 8