Palo Alto Networks researchers demonstrated how AI agents built on Google Cloud's Vertex AI platform could be compromised and turned into double agents, enabling data exfiltration, backdoor creation, and infrastructure compromise, reports SecurityWeek. The researchers found that the Per-Project, Per-Product Service Agent has excessive permissions by default, allowing attackers to obtain GCP service agent credentials and move from the AI agent's execution context into the owner's project and data storage. This transforms the AI agent from a helpful tool into an insider threat. Compromised credentials could also be used to access private container images, exposing Google's intellectual property and providing a blueprint for further vulnerabilities. Attackers could also access Artifact Registry repositories and Cloud Storage buckets containing sensitive information. A file could be manipulated for remote code execution, creating a persistent backdoor.Google addressed the issue by revising documentation and recommending Bring Your Own Service Account to enforce least-privilege execution, granting the agent only the permissions it requires. Google also noted strong controls prevent service agents from altering production images.
AI/ML, Cloud Security
Palo Alto weaponizes Vertex AI agents as double agents

(Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds


