Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
Medium Severity
Global
Date OccurredJun 16, 202619:05 UTC
Event TypeCyber Intelligence
SourceTheHackerNews
RecordedJun 16, 2026
Full Description
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastr