Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A logic flaw in the Google Cloud Vertex AI Python SDK allowed attackers to hijack AI model uploads using only a target’s public project ID, requiring no stolen credentials or prior access. By pre-registering a predictably named staging bucket, an attacker could substitute a malicious model payload that executed code inside Google’s serving infrastructure and stole OAuth tokens capable of accessing cross-tenant cloud resources. Organizations using the Vertex AI Python SDK below version 1.148.0 to upload or serve models should treat this as an urgent patching item.

Author

Tech Jacks Solutions