{"id":640981,"date":"2023-04-24T10:05:29","date_gmt":"2023-04-24T15:05:29","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/04\/24\/security-experts-found-a-major-bug-in-google-cloud\/"},"modified":"2023-04-24T10:05:29","modified_gmt":"2023-04-24T15:05:29","slug":"security-experts-found-a-major-bug-in-google-cloud","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/04\/24\/security-experts-found-a-major-bug-in-google-cloud\/","title":{"rendered":"Security experts found a major bug in Google Cloud"},"content":{"rendered":"<div id=\"article-body\">\n<p>Security experts SADA claimed to have found a severe vulnerability in the Google Cloud Platform which has since been patched by the tech giant.\u00a0<\/p>\n<p>Known as Asset Key Theft, the vulnerability would have potentially allowed threat actors to steal the private keys of Google Cloud Service Accounts. In a <a href=\"https:\/\/engineering.sada.com\/asset-key-thief-disclosure-cfae4f1778b6\" target=\"_blank\" data-url=\"https:\/\/engineering.sada.com\/asset-key-thief-disclosure-cfae4f1778b6\" rel=\"noopener\">statement<\/a><span> (opens in new tab)<\/span>, SADA said it believed the flaw &#8220;would have given attackers a persistent and reliable method for abusing a Google Cloud environment.&#8221;<\/p>\n<p>SADA notified Google of the issue in its <a href=\"https:\/\/www.techradar.com\/news\/best-cloud-hosting-providers\">cloud hosting<\/a> business via its <a href=\"https:\/\/bughunters.google.com\/about\" target=\"_blank\" data-url=\"https:\/\/bughunters.google.com\/about\" rel=\"noopener\">Bug Hunters<\/a><span> (opens in new tab)<\/span> bounty program, where researchers can alert the tech giant to flaws they find in its products in a safe and secure manner.<\/p>\n<h2 id=\"api-flaw\">API flaw<\/h2>\n<p>SADA believed that the issue was critical &#8220;due to the permission\u2019s commonality with third-party cloud security tools, such as Cloud Security Posture Management (CSPM) tools, to gather cloud inventory data from the API.&#8221;<\/p>\n<p>The flaw was found in the Google Cloud Platform API known as the Cloud Asset Inventory API. It affected all Google Cloud users who had enabled this API and who had cloudasset.assets.searchAllResources permissions on the applicable Google Cloud environment were exposed to this vulnerability.<\/p>\n<p>Once SADA reported this to Google, it reproduced the error itself to confirm its existence, before patching the vulnerability. SADA warns, however, that customers still may have been impacted by it, and the threat may have persisted after the patch.<\/p>\n<p>\u201cSupporting our customers as they transform their organizations in the cloud means constant vigilance when it comes to security,\u201d says SADA CTO Miles Ward. \u201cNo public cloud is immune from vulnerabilities, and we all must act fast, collaborate openly, and communicate transparently when we spot a vulnerability.&#8221;<\/p>\n<p>&#8220;We commend Google Cloud for how quickly and thoroughly they responded when we brought this bug to their attention. We\u2019re proud of the work SADA\u2019s engineers put into ensuring that our customers\u2019 data remains safe.&#8221;<\/p>\n<ul>\n<li>Here are the best <a href=\"https:\/\/www.techradar.com\/best\/best-cloud-storage\">cloud storage<\/a> providers right now<\/li>\n<\/ul>\n<\/div>\n<div data-hydrate=\"true\" data-reactroot id=\"slice-container-newsletterForm-articleInbodyContent\">\n<section>\n<p>Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!<\/p>\n<\/section>\n<\/div>\n<p><a href=\"https:\/\/www.techradar.com\/news\/security-experts-found-a-major-bug-in-google-cloud\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Becki Latson<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security experts SADA claimed to have found a severe vulnerability in the Google Cloud Platform which has since been patched by the tech giant.\u00a0Known as Asset Key Theft, the vulnerability would have potentially allowed threat actors to steal the private keys of Google Cloud Service Accounts. In a statement (opens in new tab), SADA said<\/p>\n","protected":false},"author":1,"featured_media":640982,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4371,20,46],"tags":[],"class_list":{"0":"post-640981","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-experts","8":"category-security","9":"category-technology"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/640981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=640981"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/640981\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/640982"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=640981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=640981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=640981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}