Google Cloud Platform Data Destruction via Cloud Build
ID: e2876680-88d0-57aa-8ed7-ec38aac925db
STIX ID: report--e2876680-88d0-57aa-8ed7-ec38aac925db
Feed Name: Cisco Talos
Cisco Talos details how attackers with cloudbuild.builds.create access can abuse Google Cloud Build triggers (e.g., GitHub PRs) to run gcloud commands under the Cloud Build service account, enabling GCS data destruction (T1485) and object encryption for impact (T1486). The report stresses this is not a GCP vulnerability but a misuse risk of default/assigned permissions, and recommends least-privilege service accounts for Cloud Build, requiring PR-based build approvals or /gcbrun limitations, enabling Object Versioning and Soft Delete, and monitoring/anomaly detection via Operations Logs for events such as CloudBuild.RunBuildTrigger, CreateBuild, storage.buckets.delete, and storage.buckets.create.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
