‘What if the AI agent you just deployed was secretly working against you?’: Vertex AI ‘double agent’ flaw exposes customer data and Google’s internal code



  • Unit 42 reveals misconfigured Vertex AI agents in Google Cloud can be hijacked into “double agents”
  • Excessive default permissions let attackers pivot, access Cloud Storage, and expose proprietary Google code
  • Google updated documentation, urging customers to use Bring Your Own Service Account (BYOSA) instead of defaults

Cloud misconfigurations are one of the biggest causes of data leaks, but now we have another form of misconfiguration to worry about – AI agents.

Unit 42, Palo Alto’s cybersecurity arm, has revealed new analysis showing how an AI agent deployed in the Google Cloud Platform (GCP) Vertex AI Agent Engine can be turned into a “double agent” – doing nefarious work while appearing to serve its intended purpose.


https://cdn.mos.cms.futurecdn.net/67QhWA3aCjTVBqs2Fxwjjk-1000-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img