Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents

Palo Alto Networks has disclosed the details of its analysis of Google Cloud Platform’s Vertex AI.

AI hack

Palo Alto Networks has shared details about how its researchers weaponized AI agents built on Google Cloud’s Vertex AI development platform.

The research focused on the Vertex Agent Engine and the Agent Development Kit (ADK), which enable developers to create, deploy, manage, and scale AI agents.

The Palo Alto Networks researchers found that these agents could be compromised by attackers and turned into ‘double agents’, enabling various types of malicious activities, including exfiltrating data, creating backdoors, and compromising infrastructure.

One of the main issues uncovered by the researchers concerns the Per-Project, Per-Product Service Agent (P4SA), which is associated with the user-deployed AI agent. A service agent is a service account that enables Google Cloud Platform (GCP) services to access resources.

The problem, according to Palo Alto, is that P4SA has excessive permissions by default. The company’s researchers showed that these permissions could be abused to obtain a GCP service agent’s credentials and leverage them to move from the AI agent’s execution context into the owner’s project and the associated data storage.

“This level of access constitutes a significant security risk, transforming the AI agent from a helpful tool into an insider threat,” the researchers explained

Advertisement. Scroll to continue reading.

In addition, they showed how an attacker could abuse the compromised P4SA credentials to gain unrestricted access to the Google project that hosts Vertex AI. An attacker could use this access to download container images from private repositories.

“These images form the core of the Vertex AI Reasoning Engine. Gaining access to this proprietary code not only exposes Google’s intellectual property, but also provides an attacker with a blueprint to find further vulnerabilities,” the researchers noted.

They also found that the compromised credentials could be used to access restricted Artifact Registry repositories containing other images that could be useful to attackers, as well as Google Cloud Storage buckets containing potentially sensitive information.

The researchers also came across a file that an attacker may be able to manipulate for remote code execution within the agent’s environment. A threat actor could use this to create a powerful and persistent backdoor.

Palo Alto has shared its findings with Google, and the tech giant has addressed the issue by revising its documentation to point out potential risks. 

Google also recommends using Bring Your Own Service Account (BYOSA) to secure Agent Engine and ensure least-privilege execution. BYOSA enables Agent Engine users to enforce the principle of least privilege, granting the agent only the permissions it requires to function.

Additionally, Google noted that strong, non-overridable controls are in place to prevent service agents from altering production images.

Related: Palo Alto Networks, Google Cloud Strike Multibillion-Dollar AI and Cloud Security Deal

Related: AI Supply Chain Attack Method Demonstrated Against Google, Microsoft Products

Related: AI Systems Vulnerable to Prompt Injection via Image Scaling Attack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Tim Byrd has been appointed Chief Information Security Officer at First Citizens Bank.

IRONSCALES has named Steve McKenzie as Chief Operating Officer.

Silvio Pappalardo has joined AuthMind as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.