Research conducted by Tenable reveals the presence of ‘ConfusedFunction’ vulnerability in Google Cloud Platform

Published:

spot_img

Tenable Research Discovers ConfusedFunction Vulnerability in Google Cloud Platform

Tenable, the Exposure Management company, has made a significant discovery in Google Cloud Platform (GCP) that has raised concerns about the security of its Cloud Function serverless compute service and Cloud Build CI/CD pipeline service.

The vulnerability, named ConfusedFunction, was identified by Tenable’s Cloud Research Team. While GCP has taken steps to address the issue for future Cloud Build accounts, existing instances remain at risk and require immediate action to mitigate potential threats.

Cloud Functions in GCP are designed to automatically scale and execute code in response to specific events. However, the deployment process for these functions inadvertently grants excessive permissions to the default Cloud Build service account, leaving them vulnerable to exploitation by attackers.

Liv Matan, Senior Research Engineer at Tenable, emphasized the importance of addressing the ConfusedFunction vulnerability, noting that the complexity of software and inter-service communication in cloud environments can lead to problematic scenarios.

GCP has confirmed that it has partially remediated the issue for Cloud Build accounts created after February 14, 2024. However, the vulnerability still persists in existing instances, prompting the recommendation for users to replace legacy Cloud Build service accounts with least-privilege service accounts to enhance security.

For more detailed technical findings and proof of concept, Tenable has provided additional information on their blog and in a technical advisory. The discovery of ConfusedFunction serves as a reminder of the ongoing challenges in maintaining secure cloud environments and the importance of proactive security measures.

spot_img

Related articles

Recent articles

Exploring Chrome 0-Day Vulnerabilities, Data Wipers, Misused Tools, and Zero-Click iPhone Attacks

Jun 09, 2025Ravie LakshmananCybersecurity / Hacking News Every security alert holds a deeper narrative. Sometimes it indicates systemic vulnerabilities being tested; other times, it's about...

Spotlight on Michelle Tolmay: Kaluza’s Chief Information Security Officer

Insights from Michelle Tolmay: Leadership and Innovation in Technology A Journey into Technology Michelle Tolmay, the Chief Information Security Officer at Kaluza, reflects on her intriguing...

OpenAI Prohibits ChatGPT Accounts Linked to Russian, Iranian, and Chinese Hackers

OpenAI Takes Action Against Malicious Use of ChatGPT OpenAI recently announced the suspension of several ChatGPT accounts linked to potentially harmful activities by Russian-speaking threat...

AI-Enhanced Identity Theft: BBB Warns of Dark Web Scammers

Scammers Selling Personal Information on the Dark Web In a disconcerting trend, scammers are increasingly posting menus of stolen personal data on the dark web,...