Two security holes in Google’s Vertex machine learning (ML) platform have been found by cybersecurity experts. If successfully exploited, these vulnerabilities might enable malevolent actors to escalate privileges and steal models from the cloud.
In an analysis released earlier this week, researchers Ofir Balassiano and Ofir Shaty of Palo Alto Networks Unit 42 stated, “We were able to escalate our privileges and gain unauthorized access to all data services in the project by exploiting custom job permissions.”
All other fine-tuned models were exfiltrated when a poisoned model was deployed in Vertex AI, creating a significant danger of a sensitive and proprietary data exfiltration assault read more about Researchers Warn of Privilege Escalation Risks in Google’s Vertex AI ML Platform.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
