Skip to content
Threat Feed

Tag

Gcp

27 briefs RSS
medium advisory

GCP Service Account Impersonation Role Grant Detection

Adversaries can gain unauthorized access to Google Cloud Platform environments by granting themselves service account impersonation roles, enabling long-term persistence and privilege escalation that survives credential rotation.

Google Cloud Platform persistence privilege-escalation cloud-security gcp
1r 1t
high advisory

OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection Vulnerability

OpenCost contains an unauthenticated file write vulnerability, tracked as GHSA-wmj8-9953-vff5, in its `/serviceKey` endpoint that allows remote attackers to overwrite the GCP service account key file (`key.json`) without any authentication or input validation, leading to service disruption, credential theft, and potential privilege escalation within Kubernetes clusters or GCP environments.

OpenCost: All versions opencost kubernetes cloud gcp vulnerability unauthenticated-access file-write
1r 4t 2i
medium advisory

GKE Pod Created With HostIPC Sharing

A privilege escalation threat in Google Kubernetes Engine (GKE) involves an attacker creating or modifying a pod to enable host Inter-Process Communication (IPC) namespace sharing, which exposes host IPC mechanisms and can lead to privilege escalation within the cluster by allowing the pod to interact directly with the underlying host's processes.

Google Kubernetes Engine gcp kubernetes privilege-escalation container-security cloud-security host-ipc
1r 2t
low advisory

GCP Pub/Sub Subscription Creation

This rule detects the creation of a subscription in Google Cloud Platform (GCP) Pub/Sub, which could indicate unauthorized access to data streams by adversaries attempting to intercept or exfiltrate sensitive information.

Google Cloud Platform Pub/Sub cloud gcp pubsub subscription
2r 2t
low advisory

GCP Logging Sink Modification for Exfiltration or Defense Evasion

Modification of a Google Cloud Platform (GCP) Logging sink is detected, potentially indicating an adversary's attempt to exfiltrate logs to an unauthorized destination or impair defenses by disabling or modifying cloud logs.

Google Cloud Platform gcp cloud exfiltration defense_evasion
2r 2t
medium advisory

GCP Storage Bucket Deletion for Impact

An adversary may delete a Google Cloud Platform (GCP) storage bucket to disrupt business operations, detected via GCP audit logs.

Google Cloud Platform +1 cloud gcp impact
2r 1t
low advisory

GCP Pub/Sub Topic Deletion for Defense Evasion

Detection of Google Cloud Platform Pub/Sub topic deletions can indicate an attempt to disrupt message flow and potentially evade defenses by impairing logging or event-driven automation.

GCP Pub/Sub gcp pubsub defense-evasion cloud
2r 2t
medium advisory

GCP Logging Sink Deletion for Defense Evasion

Detection of Google Cloud Platform (GCP) Logging sink deletion, a technique used by adversaries to impair defenses and evade detection by preventing log entries from being exported to designated destinations.

Google Cloud Platform +1 gcp logging defense-evasion
2r 1t
low advisory

GCP Pub/Sub Subscription Deletion

Detection of a Google Cloud Platform Pub/Sub subscription deletion, which can be used by adversaries to disrupt communication, evade detection, or impair defenses.

Pub/Sub gcp pubsub defense_evasion cloud
2r 2t
medium advisory

GCP Logging Bucket Deletion for Defense Evasion

Detection of a Google Cloud Platform (GCP) logging bucket deletion, which can be used by adversaries to impair defenses and evade detection by removing or modifying cloud logs.

Google Cloud Platform gcp cloud defense_evasion
2r 1t
medium advisory

GCP Virtual Private Cloud Route Deletion for Defense Evasion

An adversary may delete a Virtual Private Cloud (VPC) route in Google Cloud Platform (GCP) to disrupt network traffic flow and evade defenses.

Virtual Private Cloud gcp vpc route defense-evasion cloud
2r 2t
high advisory

GCP Account Compromise via Single-Factor Authentication

Detection of successful single-factor authentication against Google Cloud Platform (GCP) for an account without Multi-Factor Authentication (MFA) enabled, potentially leading to account compromise and unauthorized access to GCP resources.

Google Cloud Platform +1 gcp cloud authentication account-takeover
2r 2t
medium advisory

GCP Virtual Private Cloud Network Deletion

Detection of Virtual Private Cloud (VPC) network deletion in Google Cloud Platform (GCP), which can be used by an adversary to disrupt a target's network and business operations.

Virtual Private Cloud cloud gcp defense-evasion impact
2r 2t
medium advisory

GCP Service Account Disabled

Detection of a Google Cloud Platform (GCP) service account being disabled, potentially indicating malicious activity aimed at disrupting business operations by an adversary.

Google Cloud Platform gcp cloud iam impact
2r 1t
low advisory

GCP Virtual Private Cloud Route Creation for Defense Evasion

The creation of a virtual private cloud (VPC) route in Google Cloud Platform (GCP) can indicate an adversary attempting to impact the flow of network traffic for defense evasion.

Virtual Private Cloud gcp vpc route defense-evasion cloud
2r 2t
medium advisory

GCP Storage Bucket Configuration Modification

This rule detects modifications to Google Cloud Platform (GCP) storage bucket configurations, potentially indicating an adversary attempting to weaken security controls for unauthorized access or data exfiltration.

Google Cloud Storage cloud gcp defense_evasion
2r 1t
low advisory

GCP Service Account Key Creation for Persistence

An adversary may create a new key for a service account in Google Cloud Platform (GCP) to abuse the permissions assigned to that account and evade detection, potentially leading to persistent access.

Google Cloud Platform cloud gcp persistence account-manipulation
2r 1t
medium advisory

GCP Service Account Deletion

Detection of Google Cloud Platform (GCP) service account deletion, which adversaries may perform to disrupt business operations.

Google Cloud Platform gcp iam impact
2r 1t
medium advisory

GCP Authentication Failure During MFA Challenge

Detection of failed MFA challenges in Google Cloud Platform (GCP) using Google Workspace login failure events, potentially indicating credential compromise and unauthorized access attempts.

Google Cloud Platform +1 gcp cloud mfa credential-access
2r 2t 1i
medium advisory

GCP IAM Custom Role Creation

Detection of Identity and Access Management (IAM) custom role creation in Google Cloud Platform (GCP), which can indicate potential privilege escalation or persistence by adversaries creating roles with excessive permissions.

Google Cloud Platform gcp iam custom-role initial-access persistence privilege-escalation
3r 3t
low advisory

GCP Service Account Creation for Persistence

Successful creation of a new service account in Google Cloud Platform (GCP) can indicate malicious persistence, as adversaries may create these accounts to evade detection by avoiding standard user accounts.

Google Cloud Platform cloud gcp persistence iam
2r 1t
high advisory

GCP Password Spraying Detection

A single source IP is failing to authenticate into Google Workspace with multiple valid users, potentially indicating a Password Spraying attack.

Google Workspace gcp password-spraying cloud
2r 2t
high advisory

GCP Multi-Factor Authentication Disabled

Detection of disabled multi-factor authentication (MFA) for a Google Cloud Platform (GCP) user, potentially leading to unauthorized access and data exfiltration.

Google Cloud Platform +1 cloud gcp mfa persistence defense-evasion
2r 2t
low advisory

GCP IAM Service Account Key Deletion

Detection of Identity and Access Management (IAM) service account key deletion in Google Cloud Platform (GCP), potentially indicating malicious activity such as disrupting services or covering tracks after unauthorized access.

Google Cloud Platform cloud gcp iam persistence impact
2r 2t
medium advisory

GCP Firewall Rule Deletion for Defense Evasion

The deletion of firewall rules in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine is detected, potentially weakening security controls and enabling unauthorized access or data exfiltration by adversaries.

Google Cloud Platform +2 cloud defense-evasion gcp
2r 1t
low advisory

GCP Firewall Rule Creation for Defense Evasion

An adversary may create a new firewall rule in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine to weaken their target's security controls and allow more permissive ingress or egress traffic flows for their benefit, indicating a defense evasion attempt.

Google Cloud Platform +2 gcp firewall defense_evasion
2r 1t
high advisory

GCP Multiple Failed MFA Requests Imply MFA Fatigue Attack

Detection of multiple failed multi-factor authentication (MFA) requests for a single user in Google Cloud Platform (GCP) within a short time window, potentially indicating an MFA fatigue attack attempting to bypass MFA and gain unauthorized access.

Google Cloud Platform +1 gcp mfa mfa-fatigue credential-access
2r 3t