[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH9LB5ZWkNxZCBdre56JsKn5wR8hTRnrXsB4MTFhEP2U":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"9f1c8e77-3f5c-481e-ad63-89cb6acf3487","gcp-vertex-ai-service-agents-exploited-for-privilege-escalation","01d8970c-7f91-4ad9-8eca-168813297502","GCP Vertex AI Service Agents Exploited for Privilege Escalation","Palo Alto Networks discovered that Google Cloud Platform's Vertex AI service agents were configured with excessive privileges by default, allowing attackers to escalate permissions and access sensitive data across multiple GCP projects. The vulnerability stemmed from overprivileged default configurations in the Per-Project, Per-Product Service Agent (P4SA) model, which granted service accounts broader access than necessary for their intended functions. This demonstrates how cloud service defaults can create security blind spots, enabling lateral movement and data exfiltration even within trusted cloud environments. The incident highlights the critical importance of applying least privilege principles to cloud service accounts and regularly auditing automated service permissions.","**Immediate actions:**\n- Review and audit all GCP service account permissions for Vertex AI and other cloud services\n- Implement least privilege access controls for all service agents and automated processes\n- Enable detailed logging for service account activities across all cloud projects\n\n**Configuration hardening:**\n- Configure custom service account roles instead of relying on default cloud service permissions\n- Implement project-level access boundaries to prevent cross-project privilege escalation\n- Establish regular access reviews for all cloud service accounts and their associated permissions\n\n**Monitoring measures:**\n- Deploy cloud security monitoring tools to detect unusual service account activity\n- Set up alerts for cross-project access attempts by service accounts\n- Implement automated compliance checks for service account privilege configurations",[12,13,14,15,16,17],"CIS Control 3","CIS Control 6","NIST AC-2","NIST AC-6","NIST AC-3","NIST CM-2","published","2026-04-03T22:09:00.92272+00:00","2026-04-03T22:09:00.834+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fbit.ly\u002F4tmaLxA","double-agents-exposing-security-blind-spots-in-gcp-vertex-ai","Double Agents: Exposing Security Blind Spots in GCP Vertex AI",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"63bb4ec4-87e4-4994-9cfc-f9e672c833e9","2026-04-04","morning","ThreatNoir Weekend Brief — April 4","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-04\u002Fthreatnoir-morning-brief-2026-04-04.mp3"]