WhisperX tag archive

#Cloud Vulnerability

This page collects WhisperX intelligence signals tagged #Cloud Vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-20 15:23:01 · GitHub Issues

1. Google Cloud Vertex AI 安全漏洞:Vertex AI Experiments 可预测存储桶命名 (CVE-2026-2473)

Google Cloud 的核心人工智能平台 Vertex AI 被曝存在一个安全漏洞,其 Vertex AI Experiments 功能中的存储桶命名模式可被预测。该漏洞被追踪为 CVE-2026-2473,影响 Google Cloud Platform 上从 1.21.0 版本开始,直至(但不包括)1.133.0 版本的所有 `google-cloud-aiplatform` SDK。这意味着在近一年半的版本迭代中,使用 Vertex AI Experiments 功能的项目可能面临数据暴露或未授权访问的风险。 该漏洞源于 Vertex AI Experiments 组件中用于存储实验数据的 Google Cloud St...

The Lab · 2026-04-21 16:22:48 · GitHub Issues

2. Supabase Security Alert: Critical RLS Vulnerability Exposes Project Data to Public Access

A critical security vulnerability has been detected in Supabase projects, exposing database tables to public read, edit, and delete access. The flaw stems from the absence of Row-Level Security (RLS), a fundamental access control mechanism. Without RLS enabled, anyone possessing a project's URL can gain unrestricted, a...