Research conducted by Tenable reveals the presence of ‘ConfusedFunction’ vulnerability in Google Cloud Platform

Published:

spot_img

Tenable Research Discovers ConfusedFunction Vulnerability in Google Cloud Platform

Tenable, the Exposure Management company, has made a significant discovery in Google Cloud Platform (GCP) that has raised concerns about the security of its Cloud Function serverless compute service and Cloud Build CI/CD pipeline service.

The vulnerability, named ConfusedFunction, was identified by Tenable’s Cloud Research Team. While GCP has taken steps to address the issue for future Cloud Build accounts, existing instances remain at risk and require immediate action to mitigate potential threats.

Cloud Functions in GCP are designed to automatically scale and execute code in response to specific events. However, the deployment process for these functions inadvertently grants excessive permissions to the default Cloud Build service account, leaving them vulnerable to exploitation by attackers.

Liv Matan, Senior Research Engineer at Tenable, emphasized the importance of addressing the ConfusedFunction vulnerability, noting that the complexity of software and inter-service communication in cloud environments can lead to problematic scenarios.

GCP has confirmed that it has partially remediated the issue for Cloud Build accounts created after February 14, 2024. However, the vulnerability still persists in existing instances, prompting the recommendation for users to replace legacy Cloud Build service accounts with least-privilege service accounts to enhance security.

For more detailed technical findings and proof of concept, Tenable has provided additional information on their blog and in a technical advisory. The discovery of ConfusedFunction serves as a reminder of the ongoing challenges in maintaining secure cloud environments and the importance of proactive security measures.

spot_img

Related articles

Recent articles

Dubai’s Traffic Revamp: New Bridges, Lane Expansions, and Upgrades to Reduce Travel Times

Major Traffic Intersection Upgrade in Dubai: Sheikh Zayed bin Hamdan Al Nahyan Street The Roads and Transport Authority (RTA) of Dubai has embarked on an...

ANGLE Vulnerability Raises Concerns About Browser Security

Critical Security Flaw Discovered in Google’s Chromium Browser Engine A significant security vulnerability in Google’s Chromium browser engine has raised alarms globally, as researchers have...

AI-Driven Phishing Kits Overcome MFA to Steal Credentials at Scale

The Evolution of Phishing Kits: How AI is Changing the Game Cybersecurity researchers have recently identified a new wave of advanced phishing kits that are...

CISA Warns of Critical RCE Vulnerability in Sierra Wireless Routers

Significant Vulnerability Found in Sierra Wireless Routers On December 13, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning regarding a critical...