Story perspectives
Google's Vertex AI Vulnerabilities Expose Cloud Security Risks
4/2/2026
1 of 1
Story summary
- Palo Alto Networks researchers found vulnerabilities in Google's Vertex AI platform due to excessive default permissions granted to the Per-Project, Per-Product Service Agent.
- Attackers could exploit these permissions to exfiltrate credentials or compromise cloud environments.
- Google has updated documentation, recommending Bring Your Own Service Account (BYOSA) to enforce the principle of least privilege.
- Experts warn these flaws could expose Google's intellectual property and facilitate attacks on its software supply chain.
