Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Executive Summary We discovered a vulnerability in the Google Cloud Vertex AI software development kit (SDK) for Python, and responsibly
Executive Summary We discovered a vulnerability in the Google Cloud Vertex AI software development kit (SDK) for Python, and responsibly
Agentic AI is no longer theoretical. It’s already embedded across enterprises inside developer workflows, SaaS platforms, and operational pipelines. It
The browser has become the enterprise workspace. Employees, contractors, partners, and third parties use browsers to access SaaS applications, internal
These capabilities generally facilitate access to “content data” (referring to the actual content of intercepted traffic), “communications data” (also known
The CERT Coordination Center (CERT/CC) has disclosed a critical security issue affecting multiple Tenda networking devices. Tracked as CVE-2026-11405, the
Eight Greeks who were snooped on by Predator spyware sued the surveillance tech manufacturer Intellexa on Tuesday, as well as
Executive Summary We recently identified a bucket hijacking technique impacting multiple services across major cloud service providers (CSPs). The attack
The US Federal Government is committing $600 million to build one of the world’s most advanced AI infrastructure systems. Executive
Organizations are struggling to detect, investigate, and contain cloud threats before adversaries achieve their goals. The new CrowdStrike State of
Summer ‘26 vibes: international flights, Riyadh heat, and plentiful CISO conversations. Every conversation (regardless of geographic location or industry vertical)