Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Palo Alto Networks Unit 42 disclosed that Google Cloud Vertex AI Agent Engine grants its default platform-managed service account excessive OAuth scopes, allowing a compromised or malicious AI agent to steal credentials, access all Cloud Storage buckets in the project, and read internal Artifact Registry container images. The exposure affects any organization running AI agents on Agent Engine without a custom service account, and it remains active until teams replace the default configuration with Bring Your Own Service Account (BYOSA). The finding signals a broader risk pattern: as enterprises adopt managed AI platforms, default-permissive infrastructure configurations are becoming viable attack surfaces that traditional security programs have not yet been built to audit.

Author

Tech Jacks Solutions