Newsletter
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home APPLICATIONS

Severe Flaw in Google Cloud’s Cloud SQL Service Exposed Confidential Data

Real Hacker Staff by Real Hacker Staff
May 26, 2023
in APPLICATIONS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


May 26, 2023Ravie LakshmananData Safety / Cloud Security

A new security flaw has been disclosed in the Google Cloud Platform’s (GCP) Cloud SQL service that could be potentially exploited to obtain access to confidential data.

“The vulnerability could have enabled a malicious actor to escalate from a basic Cloud SQL user to a full-fledged sysadmin on a container, gaining access to internal GCP data like secrets, sensitive files, passwords, in addition to customer data,” Israeli cloud security firm Dig said.

Cloud SQL is a fully-managed solution to build MySQL, PostgreSQL, and SQL Server databases for cloud-based applications.

The multi-stage attack chain identified by Dig, in a nutshell, leveraged a gap in the cloud platform’s security layer associated with SQL Server to escalate the privileges of a user to that of an administrator role.

The elevated permissions subsequently made it possible to abuse another critical misconfiguration to obtain system administrator rights and take full control of the database server.

Cloud SQL

From there, a threat actor could access all files hosted on the underlying operating system, enumerate files, and extract passwords, which could then act as a launchpad for further attacks.

“Gaining access to internal data like secrets, URLs, and passwords can lead to exposure of cloud providers’ data and customers’ sensitive data which is a major security incident,” Dig researchers Ofir Balassiano and Ofir Shaty said.

UPCOMING WEBINAR

Zero Trust + Deception: Learn How to Outsmart Attackers!

Discover how Deception can detect advanced threats, stop lateral movement, and enhance your Zero Trust strategy. Join our insightful webinar!

Save My Seat!

Following responsible disclosure in February 2023, the issue was addressed by Google in April 2023.

Related articles

New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal

New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal

June 3, 2023

Bug affecting Android version of WhatsApp causes it to crash when a certain message is received

June 3, 2023

The disclosure comes as Google announced the availability of its Automatic Certificate Management Environment (ACME) API for all Google Cloud users to automatically acquire and renew TLS certificates for free.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: CloudcloudsConfidentialDataExposedflawGoogleserviceSevereSQL
Share76Tweet47

Related Posts

New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal

New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal

by Real Hacker Staff
June 3, 2023
0

Jun 03, 2023Ravie LakshmananEndpoint Security / Linux An analysis of the Linux variant of a new ransomware strain called BlackSuit...

Bug affecting Android version of WhatsApp causes it to crash when a certain message is received

by Real Hacker Staff
June 3, 2023
0

The Android version of popular messaging app WhatsApp is crashing whenever someone sends a specific message to a subscriber via...

Road to WWDC: What to expect from Reality Pro and AR/VR

by Real Hacker Staff
June 2, 2023
0

This year's WWDC is now right around the corner and expectations are as high as ever. The annual unveiling of...

The weather widget on Android Auto’s new Coolwalk redesign may be making a comeback

by Real Hacker Staff
June 2, 2023
0

Google began its roll out of the "Coolwalk" Android Auto redesign earlier this year which brought a split-screen view to...

This new Gmail app update will show you your top search results first

by Real Hacker Staff
June 2, 2023
0

Google has announced an update to the Gmail mobile app that introduces a change in the way users can search...

Load More
  • Trending
  • Comments
  • Latest

XMOS Launches XVF3800 High-Performance Voice Processor for Enterprise and Consumer Voice Conferencing Platforms

March 7, 2023

eSIMs Will Transform the Way You Think About Mobile Data and Security

March 7, 2023

Ant-Man: Quantumania, Netflix Power Rangers movie, and every new movie to watch

April 23, 2023

Chinese Hackers Using Russo-Ukrainian War Decoys to Target APAC and European Entities

December 7, 2022

Apple has “fully resumed” advertising on Twitter, says Musk

0

Engage with Aerospace Corp, Antaris, Orbital Reef, & Space Systems Command at TC Sessions: Space • TechCrunch

0

How to clean your Apple Watch

0

England’s Raheem Sterling back to UK amid home intrusion reports | Qatar World Cup 2022 News

0
Fiio FW5 review: These are the best-sounding wireless earbuds I’ve used yet

Fiio FW5 review: These are the best-sounding wireless earbuds I’ve used yet

June 3, 2023
Why is the debt ceiling so contentious in the United States? | Debt

Why is the debt ceiling so contentious in the United States? | Debt

June 3, 2023
I switched from an iPad to a OnePlus Pad because of fast charging

I switched from an iPad to a OnePlus Pad because of fast charging

June 3, 2023
Motorola Razr 40 series is launching soon in India

Motorola Razr 40 series is launching soon in India

June 3, 2023

Recent News

Fiio FW5 review: These are the best-sounding wireless earbuds I’ve used yet

Fiio FW5 review: These are the best-sounding wireless earbuds I’ve used yet

June 3, 2023
Why is the debt ceiling so contentious in the United States? | Debt

Why is the debt ceiling so contentious in the United States? | Debt

June 3, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here

© 2003 Real Hacker News