• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
severe flaw in google cloud's cloud sql service exposed confidential

Severe Flaw in Google Cloud’s Cloud SQL Service Exposed Confidential Data

You are here: Home / General Cyber Security News / Severe Flaw in Google Cloud’s Cloud SQL Service Exposed Confidential Data
May 26, 2023

A new security flaw has been disclosed in the Google Cloud Platform’s (GCP) Cloud SQL assistance that could be potentially exploited to obtain entry to private information.

“The vulnerability could have enabled a destructive actor to escalate from a standard Cloud SQL user to a full-fledged sysadmin on a container, attaining accessibility to inner GCP knowledge like techniques, delicate data files, passwords, in addition to client details,” Israeli cloud security organization Dig explained.

Cloud SQL is a fully-managed solution to make MySQL, PostgreSQL, and SQL Server databases for cloud-dependent applications.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The multi-phase attack chain recognized by Dig, in a nutshell, leveraged a gap in the cloud platform’s security layer linked with SQL Server to escalate the privileges of a person to that of an administrator purpose.

The elevated permissions subsequently designed it possible to abuse an additional critical misconfiguration to acquire system administrator rights and acquire full command of the databases server.

Cloud SQL

From there, a threat actor could entry all data files hosted on the fundamental functioning technique, enumerate information, and extract passwords, which could then act as a launchpad for additional attacks.

“Gaining access to inside details like tricks, URLs, and passwords can guide to exposure of cloud providers’ data and customers’ sensitive info which is a major security incident,” Dig scientists Ofir Balassiano and Ofir Shaty mentioned.

Future WEBINARZero Have confidence in + Deception: Find out How to Outsmart Attackers!

Explore how Deception can detect highly developed threats, end lateral movement, and increase your Zero Belief strategy. Sign up for our insightful webinar!

Preserve My Seat!

Following accountable disclosure in February 2023, the issue was dealt with by Google in April 2023.

The disclosure arrives as Google announced the availability of its Automatic Certification Administration Atmosphere (ACME) API for all Google Cloud people to immediately purchase and renew TLS certificates for free.

Located this report intriguing? Adhere to us on Twitter  and LinkedIn to read through a lot more exceptional written content we article.


Some pieces of this post are sourced from:
thehackernews.com

Previous Post: «Cyber Security News New Russian-Linked Malware Poses “Immediate Threat” to Energy Grids
Next Post: Critical OAuth Vulnerability in Expo Framework Allows Account Hijacking critical oauth vulnerability in expo framework allows account hijacking»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.