What happened
Unit 42 demonstrated the attack chain: calculate target's predictable GCS bucket name, pre-create it, wait for victim to upload model files, replace with malicious pickle. When Vertex AI loaded the poisoned model, the pickle was deserialized on Google's serving infrastructure.