The security intelligence platform for AI teams
AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.
Independent research. No sponsors, no paywalls, no conflicts of interest.
No new AI/LLM security issues were identified today.
Researchers discovered that AI agents deployed on Google Cloud Platform's Vertex AI could be weaponized as 'double agents' that secretly compromise systems while appearing to work normally. The vulnerability stems from excessive default permissions granted to service agents (special accounts that allow GCP services to access resources), which attackers can exploit to steal data, access restricted code, and gain unauthorized control over infrastructure. Google addressed this by revising their official documentation to explicitly explain how Vertex AI uses resources and accounts.
Fix: Google revised their official documentation to explicitly document how Vertex AI uses resources, accounts and agents.
Palo Alto Unit 42