Google Cloud Vulnerability Management: Insufficient Forensic Visibility
ID: 00600593-ca6b-54ac-8729-e369732a4628
STIX ID: report--00600593-ca6b-54ac-8729-e369732a4628
Feed Name: Mitiga
Mitiga researchers found a forensic visibility gap in Google Cloud Storage where multiple distinct actions (read, download, copy, metadata access) are recorded as a single "Object Get" event, enabling an attacker who gains control of an IAM entity to exfiltrate data to an external GCP bucket (e.g., via gsutil cp) without clear detection. The advisory documents the issue, Google’s response, and recommends mitigations such as VPC Service Controls, organization restriction headers, IAM tightening, and anomaly searches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
