logo

Google Cloud Platform Data Destruction via Cloud Build

ID: e2876680-88d0-57aa-8ed7-ec38aac925db

STIX ID: report--e2876680-88d0-57aa-8ed7-ec38aac925db

Feed Name: Cisco Talos

Date Published: 2025-02-06

Date Updated: 2026-04-27

Author: Darin Smith

...
...

Cisco Talos details how attackers with cloudbuild.builds.create access can abuse Google Cloud Build triggers (e.g., GitHub PRs) to run gcloud commands under the Cloud Build service account, enabling GCS data destruction (T1485) and object encryption for impact (T1486). The report stresses this is not a GCP vulnerability but a misuse risk of default/assigned permissions, and recommends least-privilege service accounts for Cloud Build, requiring PR-based build approvals or /gcbrun limitations, enabling Object Versioning and Soft Delete, and monitoring/anomaly detection via Operations Logs for events such as CloudBuild.RunBuildTrigger, CreateBuild, storage.buckets.delete, and storage.buckets.create.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.