Security researchers at Unit 42 disclosed ‘Vertex AI Double Agent’ on 31 March-1 April 2026, showing that any AI agent deployed through Google Cloud’s Vertex AI Agent Engine automatically receives its host’s service-account access token, project identifier, and OAuth scopes when queried. Researchers demonstrated that an agent compromised via prompt injection, a supply-chain attack, or insider access could exfiltrate these credentials without triggering alerts and use them to read every Cloud Storage bucket and restricted Artifact Registry repository in the customer’s project, bypassing expected tenant isolation. The research was published as a responsible disclosure; no confirmed real-world exploitation against a customer was reported.