Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services
ID: 953db491-bb0e-57f1-9ac4-6285e7fb3090
STIX ID: report--953db491-bb0e-57f1-9ac4-6285e7fb3090
Feed Name: GBHackers
**Executive Summary:** Tenable Research disclosed “LeakyLooker,” nine critical cross-tenant vulnerabilities in Google Looker Studio that could allow attackers to bypass isolation, steal or modify data from services like BigQuery, Cloud Storage, and SQL databases via zero-click and one-click techniques (e.g., alias injection, sticky credential cloning, and covert SQL exfiltration); Google has patched the issues globally but organizations should audit report/viewer access and revoke unused data connector permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
