‘What if the AI ​​agent you just deployed was secretly working against you?’: Vertex AI ‘double agent’ bug exposes customer data and Google’s internal code



  • Unit 42 reveals poorly configured Vertex AI agents on Google Cloud can be hijacked by “double agents”
  • Excessive default permissions allow attackers to bypass, access Cloud Storage, and reveal Google’s identity code
  • Google’s updated documentation, urging customers to use Bring Your Own Service Account (BYOSA) instead of the default

Cloud misconfiguration is one of the biggest causes of data leaks, but now we have another form of misconfiguration to worry about – AI agents.

Unit 42, Palo Alto’s cybersecurity arm, has released a new analysis that shows how the AI ​​agent used in the Google Cloud Platform (GCP) Vertex AI Agent Engine can be turned into a “double agent” – doing a bad job while appearing to serve its purpose.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

spot_img

More like this

NordVPN make Meshnet free to use

NordVPN promises urgent Mac app update after users call...

The latest NordVPN macOS update has caused significant interface lag and dropped connections for users.Frustrated customers took...
The Last of Us Part 2 Remastered Joel Miller looking up

A former Xbox boss thinks Naughty Dog’s decision to...

Former Microsoft executive Laura Fryer says Naughty Dog's decision to cancel The Last of Us Online ...
My New Ikea Smart Lamp is a Glowing Donut of Happiness

This Donut Smart Lamp From Ikea Has Super Bright...

Benefits ...