What happened
Researchers at Palo Alto Networks Unit 42 uncovered a vulnerability in the Google Cloud Vertex AI SDK for Python that allowed an outside attacker — one with zero access to a target's project — to intercept and replace machine learning model uploads through a technique they dubbed 'Pickle in the Middle.' The attack exploits predictable Cloud Storage bucket naming conventions, enabling an adversary to pre-register a bucket and have malicious code execute inside Google's own serving infrastructure. Google received the report through its bug bounty program and no exploitation in the wild has been observed. Separately, security journalist Brian Krebs published an investigation into The Gentlemen, a ransomware collective that has rapidly climbed to become the second most active group by confirmed victim count, fueled by a recruitment model that hands affiliates a 90 percent cut of ransom proceeds.
Why it matters for your business
The Vertex AI flaw illustrates that AI and MLOps pipelines carry supply-chain risks that many security teams have not yet fully evaluated — an attacker controlling model inference could corrupt outputs, exfiltrate data, or pivot deeper into cloud environments. Organizations running model training or deployment workflows on managed cloud platforms should audit storage bucket naming policies and verify artifact integrity before promotion to production. The Gentlemen's aggressive affiliate economics — a 90/10 revenue split — is a meaningful signal that the group will continue to scale; a higher affiliate share attracts more skilled operators, which typically translates to larger, more sophisticated intrusions. Executives should treat this as a prompt to review incident response playbooks, offline backup integrity, and cyber insurance coverage before an attack forces those conversations.
What to watch next
Google has not yet published a full public advisory detailing the patch scope for the Vertex AI SDK, so teams should monitor the official release notes and apply any forthcoming SDK updates immediately. On the ransomware front, Krebs's identification of a likely administrator behind The Gentlemen could trigger law-enforcement action, operational disruption, or a rebranding — patterns that historically shift affiliate activity toward successor groups. Both stories are likely to generate follow-on technical disclosures in the coming weeks, warranting close attention from security and cloud engineering leads.
