Research conducted by Tenable reveals the presence of ‘ConfusedFunction’ vulnerability in Google Cloud Platform

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Tenable Research Discovers ConfusedFunction Vulnerability in Google Cloud Platform

Tenable, the Exposure Management company, has made a significant discovery in Google Cloud Platform (GCP) that has raised concerns about the security of its Cloud Function serverless compute service and Cloud Build CI/CD pipeline service.

The vulnerability, named ConfusedFunction, was identified by Tenable’s Cloud Research Team. While GCP has taken steps to address the issue for future Cloud Build accounts, existing instances remain at risk and require immediate action to mitigate potential threats.

Cloud Functions in GCP are designed to automatically scale and execute code in response to specific events. However, the deployment process for these functions inadvertently grants excessive permissions to the default Cloud Build service account, leaving them vulnerable to exploitation by attackers.

Liv Matan, Senior Research Engineer at Tenable, emphasized the importance of addressing the ConfusedFunction vulnerability, noting that the complexity of software and inter-service communication in cloud environments can lead to problematic scenarios.

GCP has confirmed that it has partially remediated the issue for Cloud Build accounts created after February 14, 2024. However, the vulnerability still persists in existing instances, prompting the recommendation for users to replace legacy Cloud Build service accounts with least-privilege service accounts to enhance security.

For more detailed technical findings and proof of concept, Tenable has provided additional information on their blog and in a technical advisory. The discovery of ConfusedFunction serves as a reminder of the ongoing challenges in maintaining secure cloud environments and the importance of proactive security measures.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

France outlines 2035 national security plan emphasizing military transformation and technological independence

MILAN — French President Emmanuel Macron announced a comprehensive national security plan for 2035, emphasizing military transformation and technological independence in response to escalating...

Ransomware Developer Sentenced to 13 Years in Switzerland Amid Rising Cyber Threats

A Ukrainian IT specialist has been sentenced to nearly 13 years in prison by a Zurich court for his role in developing ransomware that...

Cybersecurity Awareness Essential to Combat Identity Theft and Financial Scams

Inadequate cybersecurity can lead to identity theft and significant financial loss, as highlighted by the Federal Deposit Insurance Corporation (FDIC). Scammers primarily aim to...

SimuPhish Advocates for Continuous Human Risk Management to Combat AI-Driven Cyber Threats in the Middle East

SimuPhish co-founders Shubh Arya and Hritik Jain explain why continuous behavioural intelligence is essential for building workforce cyber resilience As AI-driven threats become increasingly sophisticated,...