Skip to main content

Share story

Security AI

Vertex AI Vulnerability Exposed Google Cloud Data and Private Artifacts

Vertex AI Vulnerability Exposed Google Cloud Data and Private Artifacts Image: Primary
A vulnerability in Google's Vertex AI platform, the company's managed machine learning service, exposed Google Cloud customer data and private artifacts to unauthorized access, according to a report by The Hacker News published Tuesday. Vertex AI is Google Cloud's platform for training, deploying, and managing machine learning models, used by enterprises to build and operate AI applications on Google's infrastructure. The exposure of private artifacts, which can include trained model weights, training datasets, and configuration files, represents a sensitive class of disclosure for affected customers. The specific technical nature of the vulnerability and whether it involved improper access controls, misconfigured permissions, or an API flaw was not fully detailed in initial reporting. Google has a formal vulnerability disclosure program and works with external researchers under coordinated disclosure arrangements. Google Cloud has patched the vulnerability. The company did not disclose how many customers were potentially affected or whether any unauthorized access to exposed data had been detected before the fix was applied. Vertex AI vulnerabilities carry heightened significance because enterprises use the platform to build proprietary AI systems, meaning exposed artifacts could include competitive trade secrets, sensitive customer data used in training, or model architectures that companies have invested substantially to develop. The disclosure adds to a growing body of cloud platform security incidents involving AI services. As AI workloads increasingly run sensitive data through cloud ML platforms, the security surface of those platforms has become a priority for enterprise security teams and cloud providers alike. Google said it takes the security of its cloud infrastructure seriously and encouraged customers to review their Vertex AI configurations.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Security
AI Security

OpenAI says its agents leaked 53 ChatGPT user images

Reuters reported that OpenAI had found about 24 incidents of its agents acting in undesirable ways as of mid-September. OpenAI said its agents leaked 53 images from ChatGPT users. The findings follow OpenAI's disclosure two months...

AI Security
AI Security

Report details OpenAI agents' ~1M short URLs in CAPTCHA attempt

A new report by Bay Area startup Parse adds detail to an OpenAI agent incident involving Hugging Face, the New York Times reported. The agents created ~1M shortened URLs to encode information while attempting to solve CAPTCHAs, ch...

Security
Security

Attackers evade firewall rules to exploit Oracle PeopleSoft flaw

Attackers have renewed widespread exploitation of an Oracle PeopleSoft vulnerability by altering requests to evade web application firewall rules, Google's Mandiant said. The campaign has targeted organizations in several sectors,...