Monday, June 30, 2025

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
  • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » Google Vulnerability: ConfusedFunctions Leads To Data Access

SBN

Google Vulnerability: ConfusedFunctions Leads To Data Access

by Wajahat Raja on August 7, 2024

Cybersecurity researchers, as of recent, have discovered a Google vulnerability impacting the Cloud Functions service. The Google vulnerability being categorized as one pertaining to privilege escalation, has been named ConfusedFunctions. In this article, we’ll dive into the details of the flaw and how it can be exploited by cybercriminals.

ConfusedFunctions Google Vulnerability Details

Before we dive into the details of the Google vulnerability, let’s look at what the service actually does. Cloud Functions is basically a serverless execution environment in which developers can create single-purpose functions.

These functions can be triggered in response to specific Cloud events and do not require server management or updating a framework. The initial problem that was identified by Tenable was related to a Cloud Build service account.

Techstrong Gang Youtube
AWS Hub

The account is created in the background and linked to a Cloud build instance by default when a Cloud Function is created or updated. This essentially gives a way of entry to threat actors for initiating potential malicious activity owing to its excessive permissions.

To ensure protection against such exploits, it’s important to comprehend that these permissions are what give threat actors the ability of creating and updating Cloud Function and helping them in leveraging the loophole.

ConfusedFunctions Google Vulnerability Exploit

According to the information available, a potential threat actor can exploit this Google vulnerability to escalate privileges to the Default Cloud Build Service Account. Doing so would allow them to access numerous services such as Cloud Build, artifact and container registry, storage, and more.

Unauthorized access to such an extent can be detrimental for the targeted victims as it would allow threat actors to move laterally within a network, allowing them to expand their attack surface. With such control, they can easily update or even delete data on the compromised devices.

Google’s Response To The Flaw

After the disclosure, Google has now updated certain functions, such as the Cloud Build by using the computer engine default services account. The upgrade prevents misuse, which in turn minimizes the risk of exposure.

However, it’s important to mention here that these changes are not applicable to the latest version. Providing insight into the fix, Liv Matan, a researcher at Tenable, has said:

“While the GCP fix has reduced the severity of the problem for future deployments, it didn’t completely eliminate it. That’s because the deployment of a Cloud Function still triggers the creation of the aforementioned GCP services. As a result, users must still assign minimum but still relatively broad permissions to the Cloud Build service account as part of a function’s deployment.”

Conclusion

ConfusedFunctions vulnerability highlights the critical importance of robust cloud security measures. While Google has taken steps to mitigate the issue for future deployments, existing instances remain vulnerable. Organizations using Google Cloud Platform should review and adjust their permissions and security protocols to protect against potential exploits.

Given the severity and the aftermath of a potential exploit, vigilance and proactive security practices are essential to safeguard sensitive data and prevent unauthorized access, ensuring the integrity of cloud-based operations.

The source for this piece includes articles in The Hacker News and Candid Technology.

The post Google Vulnerability: ConfusedFunctions Leads To Data Access appeared first on TuxCare.

*** This is a Security Bloggers Network syndicated blog from TuxCare authored by Wajahat Raja. Read the original post at: https://tuxcare.com/blog/google-vulnerability-confusedfunctions-leads-to-data-access/

August 7, 2024August 7, 2024 Wajahat Raja Cloud Build service account, Cloud Functions vulnerability, ConfusedFunction exploit, Cybersecurity News, cybersecurity research, Privilege Escalation
  • ← The C-Suite Conundrum: Are Senior Executives the Achilles’ Heel of Cybersecurity?
  • Simplifying Compliance Through Automation →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Securing Vibe Coding: Addressing the Security Challenges of AI-Generated Code
How to Spot and Stop Security Risks From Unmanaged AI Tools

Podcast

Listen to all of our podcasts

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

ThreatLocker

Most Read on the Boulevard

N. Korean Group BlueNoroff Uses Deepfake Zoom Calls in Crypto Scams
‘IntelBroker’ Hacker Arrested for Wave of High-Profile Data Breaches
Abstract Security Adds Data Lake to Reduce Storage Costs
NIST’s CURBy Uses Quantum to Verify Randomness of Numbers
How to Protect Your Drupal Site From Cyberattacks
Cybersecurity Snapshot: U.S. Gov’t Urges Adoption of Memory-Safe Languages and Warns About Iran Cyber Threat
AI vs. AI: How Deepfake Attacks Are Changing Authentication Forever
The Hacktivist Cyber Attacks in the Iran-Israel Conflict
Best SAST Solutions: How to Choose Between the Top 11 Tools in 2025
Frequently Asked Questions About Iranian Cyber Operations

Industry Spotlight

Russian Throttling of Cloudflare ‘Renders Many Websites Barely Usable’
Cloud Security Cybersecurity Data Security Featured Industry Spotlight Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight 

Russian Throttling of Cloudflare ‘Renders Many Websites Barely Usable’

June 30, 2025 Jeffrey Burt | 4 hours ago 0
WhatsApp BANNED by House Security Goons — But Why?
Application Security Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security DevOps Endpoint Featured Governance, Risk & Compliance Humor Incident Response Industry Spotlight Mobile Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

WhatsApp BANNED by House Security Goons — But Why?

June 24, 2025 Richi Jennings | Jun 24 0
Scattered Spider Targets Aflac, Other Insurance Companies
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Industry Spotlight Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threat Intelligence 

Scattered Spider Targets Aflac, Other Insurance Companies

June 22, 2025 Jeffrey Burt | Jun 22 0

Top Stories

Sysdig Extends AI Agent Reach Across Portfolio
Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Sysdig Extends AI Agent Reach Across Portfolio

June 30, 2025 Michael Vizard | 1 hour ago 0
NIST’s CURBy Uses Quantum to Verify Randomness of Numbers
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

NIST’s CURBy Uses Quantum to Verify Randomness of Numbers

June 29, 2025 Jeffrey Burt | Yesterday 0
‘IntelBroker’ Hacker Arrested for Wave of High-Profile Data Breaches
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

‘IntelBroker’ Hacker Arrested for Wave of High-Profile Data Breaches

June 28, 2025 Jeffrey Burt | 2 days ago 0

Security Humor

Randall Munroe’s XKCD ‘Interoperability’

Randall Munroe’s XKCD ‘Interoperability’

Download Free eBook

Managing the AppSec Toolstack

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2025 Techstrong Group Inc. All rights reserved.
×