<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Vertex AI - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vertex-ai/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:32:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vertex-ai/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthorized GCP Vertex AI Credential Usage via Impossible Travel</title><link>https://feed.craftedsignal.io/briefs/2026-10-gcp-vertex-ai-impossible-travel/</link><pubDate>Wed, 07 Oct 2026 16:32:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gcp-vertex-ai-impossible-travel/</guid><description>Adversaries are utilizing stolen GCP user or service account credentials to perform unauthorized AI tasks across geographically distant locations, indicating LLMjacking and credential abuse.</description><content:encoded><![CDATA[<p>This threat involves the unauthorized use of stolen GCP Vertex AI credentials to perform LLM-based tasks such as content generation and token counting. Adversaries are actively leveraging compromised identities to execute requests from geographically disparate regions within short timeframes, a phenomenon described as 'impossible travel.' This behavior is a key indicator of 'LLMjacking,' where attackers exploit cloud-hosted AI resources for illicit purposes. Organizations relying on GCP Vertex AI must monitor audit activity to identify authentication events from sources that defy physical travel constraints. This pattern is often observed with stolen session tokens or service account keys, allowing threat actors to maintain persistent access and consume cloud-based AI resources without detection. Defenders should focus on mapping authenticated principals to source IP geolocation data to identify anomalous usage patterns that correlate with credential theft or account takeover.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker obtains valid GCP user or service account credentials through phishing, key theft, or exposed environment variables.</li>
<li>The attacker initiates an AI request (e.g., PredictionService.GenerateContent) from an initial source IP location.</li>
<li>A short time later, the same authenticated principal is used from a second source IP located significantly far from the first.</li>
<li>The geographical distance and time delta between these events imply a travel speed exceeding 800 km/h.</li>
<li>The attacker continues to invoke Vertex AI services to perform resource-intensive tasks such as large-scale content generation or token consumption.</li>
<li>The adversary achieves their objective, which may include data exfiltration via AI processing or unauthorized usage of expensive cloud AI infrastructure at the victim's expense.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful attacks lead to unauthorized consumption of expensive cloud AI resources, potential data exfiltration via malicious prompts, and the compromise of sensitive organizational service accounts. This activity increases cloud expenditure and exposes internal data to unauthorized manipulation.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Deploy detection logic to monitor GCP Vertex AI audit logs for authentication events showing impossible travel (distance &gt;= 500 km, speed &gt;= 800 km/h).</li>
<li>Audit all IAM bindings for service accounts that interact with Vertex AI to ensure adherence to the principle of least privilege.</li>
<li>If an impossible travel alert is confirmed, rotate credentials, revoke active sessions, and review IAM logs for unauthorized key creation or modifications.</li>
<li>Segment multi-region CI/CD pipelines to use region-scoped service accounts rather than a single global identity to reduce false positives in geolocation telemetry.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>cloud</category><category>credential-access</category><category>llmjacking</category><category>gcp</category></item></channel></rss>