Unit 42 researchers discovered a 'double agent' vulnerability in Google Cloud's Vertex AI Agent Engine, where default overprivileged service agent (P4SA) credentials could be exploited to gain unauthorized access to consumer project Cloud Storage buckets, restricted Google-internal Artifact Registry container images (including

13m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryFrom Agent to Storage Admin: Taking Over Consumer ResourcesUnauthorized Access to Google's Internals: Downloading Restricted Producer ImagesMisconfigured Artifact Registry Exposes Restricted ImagesTenant Project Access Reveals Google's Internal ResourcesA Recipe for Remote Code ExecutionBeyond the Project: Overly Permissive Scopes and the Threat to Workspace DataMitigation and Collaboration With GoogleConclusionAdditional Resources

Sort: