← Back to feed
research Unit 42

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42

Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more.

T1190
Read the full story Unit 42 →

Related Coverage

research This month in security with Tony Anscombe – July 2026 edition ESET Research · Jul 31 research Network Anomaly Detection in KATA Kaspersky Securelist · Jul 31 research The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version Unit 42 · Jul 31