← Back to feed
research Unit 42

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42

Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more.

T1190
Read the full story Unit 42 →

Related Coverage

research HTTP/3 in Burp Suite - it’s time to find a bigger wordlist PortSwigger Research · Sep 23 research The Lure Isn't The Malware. It's Your Logo. Recorded Future · Sep 23 research Looking for free Robux? Here’s what’s real, and what’s a scam ESET Research · Sep 22