Monday, June 5, 2023
AI Home Security
No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
No Result
View All Result
Morning News
No Result
View All Result
Home Cyber Security

Severe Flaw in Google Cloud’s Cloud SQL Service Exposed Confidential Data

justmattg by justmattg
May 26, 2023
in Cyber Security
0
Severe Flaw in Google Cloud’s Cloud SQL Service Exposed Confidential Data
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


May 26, 2023Ravie LakshmananData Safety / Cloud Security

Google Cloud's Cloud SQL Service

A new security flaw has been disclosed in the Google Cloud Platform’s (GCP) Cloud SQL service that could be potentially exploited to obtain access to confidential data.

“The vulnerability could have enabled a malicious actor to escalate from a basic Cloud SQL user to a full-fledged sysadmin on a container, gaining access to internal GCP data like secrets, sensitive files, passwords, in addition to customer data,” Israeli cloud security firm Dig said.

Cloud SQL is a fully-managed solution to build MySQL, PostgreSQL, and SQL Server databases for cloud-based applications.

The multi-stage attack chain identified by Dig, in a nutshell, leveraged a gap in the cloud platform’s security layer associated with SQL Server to escalate the privileges of a user to that of an administrator role.

The elevated permissions subsequently made it possible to abuse another critical misconfiguration to obtain system administrator rights and take full control of the database server.

Cloud SQL

From there, a threat actor could access all files hosted on the underlying operating system, enumerate files, and extract passwords, which could then act as a launchpad for further attacks.

“Gaining access to internal data like secrets, URLs, and passwords can lead to exposure of cloud providers’ data and customers’ sensitive data which is a major security incident,” Dig researchers Ofir Balassiano and Ofir Shaty said.

UPCOMING WEBINAR

Zero Trust + Deception: Learn How to Outsmart Attackers!

Discover how Deception can detect advanced threats, stop lateral movement, and enhance your Zero Trust strategy. Join our insightful webinar!

Save My Seat!

Following responsible disclosure in February 2023, the issue was addressed by Google in April 2023.

The disclosure comes as Google announced the availability of its Automatic Certificate Management Environment (ACME) API for all Google Cloud users to automatically acquire and renew TLS certificates for free.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

READ ALSO

Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering

Want Sustainable Security? Find Middle Ground Between Tech & Education

Related Posts

Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering
Cyber Security

Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering

June 5, 2023
Want Sustainable Security? Find Middle Ground Between Tech & Education
Cyber Security

Want Sustainable Security? Find Middle Ground Between Tech & Education

June 4, 2023
FTC Slams Amazon with $30.8M Fine for Privacy Violations Involving Alexa and Ring
Cyber Security

FTC Slams Amazon with $30.8M Fine for Privacy Violations Involving Alexa and Ring

June 4, 2023
Everything You Need to Know
Cyber Security

Streamers Ditch Netflix for Dark Web After Password Sharing Ban

June 4, 2023
EC-Council’s Certified CISO Hall of Fame Report 2023
Cyber Security

EC-Council’s Certified CISO Hall of Fame Report 2023

June 4, 2023
Influence Operator Dragonbridge Floods Social Media in Sprawling Cyber Campaign
Cyber Security

‘Picture-in-Picture’ Obfuscation Spoofs Delta, Kohl’s for Credential Harvesting

June 3, 2023
Next Post
UK government response to Biometrics Commissioner sidesteps tough questions

UK MPs examine Met police use of facial recognition

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

February 13, 2023
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

February 11, 2023
Do you know who is watching you?

Do you know who is watching you?

January 2, 2023
The New Threats to Cryptocurrency Users

The New Threats to Cryptocurrency Users

February 12, 2023
PopID announces big customer deployment for face biometric payments in UAE

PopID announces big customer deployment for face biometric payments in UAE

February 14, 2023

EDITOR'S PICK

Twitter Denies Hacking Claims, Assures Leaked User Data Not from its System

Twitter Denies Hacking Claims, Assures Leaked User Data Not from its System

January 15, 2023
Open Source Vulnerabilities Still Pose a Big Challenge for Security Teams

Open Source Vulnerabilities Still Pose a Big Challenge for Security Teams

March 24, 2023
North Korean Hackers Targeting Healthcare with Ransomware to Fund its Operations

North Korean Hackers Targeting Healthcare with Ransomware to Fund its Operations

February 12, 2023
Everything You Need to Know

‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month

March 26, 2023

About

We bring you the best news & updates related to Home security, Cyber security and Biometric technology. Keep visiting our website for latest updates.

Follow us

Categories

  • Biometric Technology
  • Cyber Security
  • Home Security

Recent Posts

  • Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering
  • Want Sustainable Security? Find Middle Ground Between Tech & Education
  • FTC Slams Amazon with $30.8M Fine for Privacy Violations Involving Alexa and Ring
  • Streamers Ditch Netflix for Dark Web After Password Sharing Ban
  • Privacy Policy
  • Contact Us

© 2023 AI Home Security - All rights reserved.

No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology

© 2023 AI Home Security - All rights reserved.