Veraset A.I CyberSecurity Scoring
Veraset
Company Information
Website:http://www.veraset.com
Employees number:11
Number of followers:1,274
NAICS:518
Industry Type:Data Infrastructure and Analytics
Homepage:veraset.com
Veraset Risk Score (AI oriented)
Between 700 and 749
VerasetData Infrastructure and Analytics
Updated:
07/07/2026
07/07/2026
749/1000
Moderate
Ba
Veraset Global Score (TPRM)
xxxx
VerasetData Infrastructure and Analytics
Score locked

VerasetModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
749
JUNE 2026
748
MAY 2026
748
APRIL 2026
748
MARCH 2026
748
FEBRUARY 2026
748
JANUARY 2026
748
DECEMBER 2025
748
NOVEMBER 2025
752
Vulnerability
01 Nov 2025 • Veraset
Google and Fortune 500 companies: Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious Code
Critical 'Rogue Agent' Vulnerability in Google Cloud’s Dialogflow CX Exposed AI Chatbots to Persistent Attacks
747
CRITICAL-5
GOOVER1783448669
Critical "Rogue Agent" Vulnerability in Google Cloud’s Dialogflow CX Exposed AI Chatbots to Persistent Attacks
Security researchers at Varonis Threat Labs disclosed a severe vulnerability in Google Cloud Platform’s (GCP) Dialogflow CX, dubbed "Rogue Agent," which allowed attackers to inject malicious code into AI-powered chatbot pipelines with minimal permissions. The flaw, patched between April and June 2026, could enable large-scale data exfiltration and phishing campaigns while remaining undetected in standard logs.
### How the Exploit Worked
The vulnerability stemmed from Playbook Code Blocks, a Dialogflow CX feature that lets developers embed custom Python logic within a Google-managed execution environment. Researchers found that:
- Shared execution environments: All agents in the same GCP project used the same Cloud Run instance, where a critical file (`code_execution_env.py`) responsible for executing Python code via `exec()` was writable and lacked restrictions.
- Low-privilege access: Attackers only needed the `dialogflow.playbooks.update` permission (scopable to a single agent) to overwrite the file, gaining control over shared session variables, including conversation history.
- Persistent compromise: Malicious code could exfiltrate data, impersonate legitimate responses, and inject phishing prompts (e.g., fake reauthentication requests) without detection. Attackers could later restore the original configuration, erasing traces in Cloud Logging.
### Amplified Risks
Two additional flaws worsened the impact:
1. VPC Service Controls (VPC-SC) bypass: Cloud Run’s unrestricted outbound internet access allowed attackers to use the environment as a covert data-exfiltration proxy, even when VPC-SC was enforced.
2. IMDS credential leakage: Exposure of the Instance Metadata Service (IMDS) enabled retrieval of Google-managed service account tokens, violating isolation principles despite their limited privileges.
### Disclosure & Response
Varonis reported the vulnerability to Google in November 2025. Google deployed an initial fix in April 2026, with a full resolution by June 2026. No in-the-wild exploitation was confirmed before the patch.
### Broader Context
"Rogue Agent" follows other AI-platform vulnerabilities disclosed by Varonis, including:
- Reprompt (Microsoft Copilot Personal)
- SearchLeak (Microsoft Copilot Enterprise, patched as CVE-2026-42824 with critical severity)
The incident underscores the expanding attack surface as 80% of Fortune 500 companies now use AI agents, increasing risks across cloud platforms. Organizations using Dialogflow CX with Playbook Code Blocks before the patch were advised to audit logs for anomalies, review configurations, and monitor for suspicious activity.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
752
SEPTEMBER 2025
752
AUGUST 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Veraset ??
What was Veraset's A.I Rankiteo Cyber Score in June 2026 ??
What was Veraset's A.I Rankiteo Cyber Score in May 2026 ??
What was Veraset's A.I Rankiteo Cyber Score in April 2026 ??
What was Veraset's A.I Rankiteo Cyber Score in March 2026 ??
What was Veraset's A.I Rankiteo Cyber Score in February 2026 ??
What was Veraset's A.I Rankiteo Cyber Score in January 2026 ??
What was Veraset's A.I Rankiteo Cyber Score in December 2025 ??
What was Veraset's A.I Rankiteo Cyber Score in November 2025 ??
What was Veraset's A.I Rankiteo Cyber Score in October 2025 ??
What was Veraset's A.I Rankiteo Cyber Score in September 2025 ??
What was Veraset's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Veraset's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Veraset ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Veraset's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?