Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Veraset

Veraset Vendor Cyber Rating & Cyber Score

veraset.com

Veraset delivers high-quality, pseudonymized location data to Fortune 500 companies, universities, and cutting edge startups sourced directly from apps, SDKs, and leading aggregators. Organizations rely on Veraset to power their decision-making, analytics platforms, and innovative research while maintaining the highest standards for compliance and consumer privacy.


Veraset A.I CyberSecurity Scoring

Veraset
Company Information
Website:http://www.veraset.com
Employees number:11
Number of followers:1,274
NAICS:518
Industry Type:Data Infrastructure and Analytics
Homepage:veraset.com
Veraset Risk Score (AI oriented)
Between 700 and 749
logo
VerasetData Infrastructure and Analytics
Updated:
07/07/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Veraset Global Score (TPRM)
xxxx
logo
VerasetData Infrastructure and Analytics
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Veraset
VerasetModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
749Before Incident
JUNE 2026
748Before Incident
MAY 2026
748Before Incident
APRIL 2026
748Before Incident
MARCH 2026
748Before Incident
FEBRUARY 2026
748Before Incident
JANUARY 2026
748Before Incident
DECEMBER 2025
748Before Incident
NOVEMBER 2025
752Before Incident
Vulnerability
01 Nov 2025Veraset
Google and Fortune 500 companies: Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious Code

Critical 'Rogue Agent' Vulnerability in Google Cloud’s Dialogflow CX Exposed AI Chatbots to Persistent Attacks

747After Incident
CRITICAL-5
GOOVER1783448669
Critical "Rogue Agent" Vulnerability in Google Cloud’s Dialogflow CX Exposed AI Chatbots to Persistent Attacks Security researchers at Varonis Threat Labs disclosed a severe vulnerability in Google Cloud Platform’s (GCP) Dialogflow CX, dubbed "Rogue Agent," which allowed attackers to inject malicious code into AI-powered chatbot pipelines with minimal permissions. The flaw, patched between April and June 2026, could enable large-scale data exfiltration and phishing campaigns while remaining undetected in standard logs. ### How the Exploit Worked The vulnerability stemmed from Playbook Code Blocks, a Dialogflow CX feature that lets developers embed custom Python logic within a Google-managed execution environment. Researchers found that: - Shared execution environments: All agents in the same GCP project used the same Cloud Run instance, where a critical file (`code_execution_env.py`) responsible for executing Python code via `exec()` was writable and lacked restrictions. - Low-privilege access: Attackers only needed the `dialogflow.playbooks.update` permission (scopable to a single agent) to overwrite the file, gaining control over shared session variables, including conversation history. - Persistent compromise: Malicious code could exfiltrate data, impersonate legitimate responses, and inject phishing prompts (e.g., fake reauthentication requests) without detection. Attackers could later restore the original configuration, erasing traces in Cloud Logging. ### Amplified Risks Two additional flaws worsened the impact: 1. VPC Service Controls (VPC-SC) bypass: Cloud Run’s unrestricted outbound internet access allowed attackers to use the environment as a covert data-exfiltration proxy, even when VPC-SC was enforced. 2. IMDS credential leakage: Exposure of the Instance Metadata Service (IMDS) enabled retrieval of Google-managed service account tokens, violating isolation principles despite their limited privileges. ### Disclosure & Response Varonis reported the vulnerability to Google in November 2025. Google deployed an initial fix in April 2026, with a full resolution by June 2026. No in-the-wild exploitation was confirmed before the patch. ### Broader Context "Rogue Agent" follows other AI-platform vulnerabilities disclosed by Varonis, including: - Reprompt (Microsoft Copilot Personal) - SearchLeak (Microsoft Copilot Enterprise, patched as CVE-2026-42824 with critical severity) The incident underscores the expanding attack surface as 80% of Fortune 500 companies now use AI agents, increasing risks across cloud platforms. Organizations using Dialogflow CX with Playbook Code Blocks before the patch were advised to audit logs for anomalies, review configurations, and monitor for suspicious activity.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Conversation history, session variables, potentially sensitive user dataSystems Affected: Google Cloud Dialogflow CX with Playbook Code Blocks enabledOperational Impact: Potential large-scale data exfiltration, phishing campaigns, and undetected malicious activityBrand Reputation Impact: Potential erosion of trust in AI-powered chatbot securityIdentity Theft Risk: High (if PII was exposed)
DATA BREACH
Conversation historySession variablesPotentially sensitive user dataSensitivity Of Data: High (if PII or business-sensitive data was involved)Data Exfiltration: Possible via Cloud Run outbound internet accessPersonally Identifiable Information: Possible
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Veraset ?
?
What was Veraset's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Veraset's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Veraset's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Veraset's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Veraset's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Veraset's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Veraset's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Veraset's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Veraset's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Veraset's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Veraset's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Veraset's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Veraset ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Veraset's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Veraset Cyber Scoring History | Rankiteo