INTEL_REPORT
Palo Alto Networks Unit 42 · published 6/16/2026, 10:00:29 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42 . Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Menu Tools ATOMs Security Consulting About Us Under Attack? Threat R…
https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model
sha256:75d3775790607a79773dd17271b22ee276c94cd34d7893a2e9998ef6b4ca7d85
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| bucket.exists |
| Open → |
| domain | gcp-sa-aiplatform.iam.gserviceaccount.com | Open → |
| domain | model.upload | Open → |
| domain | storage.legacybucketreader | Open → |
| domain | storage.objectcreator | Open → |
| domain | storage.objectviewer | Open → |
| domain | google.storage.object.finalize | Open → |
| domain | model.joblib | Open → |
| domain | oogle.storage.object.finalize | Open → |
| domain | aiplatform.model.upload | Open → |
| domain | us-docker.pkg.dev | Open → |
| domain | aiplatform.endpoint.create | Open → |
| domain | iam.gserviceaccount.com | Open → |