DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home News

Tenable Uncovers ConfusedComposer Vulnerability In Google Cloud Platform

DigitalCIO Bureau by DigitalCIO Bureau
April 24, 2025
in News, Tech News
0
Tenable Reveals Vulnerability dubbed ConfusedFunction in Google Cloud Platform
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Tenable has uncovered a privilege escalation vulnerability in Google Cloud Composer (GCP) named ConfusedComposer. The vulnerability lets attackers with edit permissions in Cloud Composer to escalate privileges and gain access to a high-level service account with broad permissions across GCP.

Cloud Composer uses Cloud Build, a fully managed continuous integration and delivery (CI/CD) service in GCP, to install custom PyPI packages, using a highly privileged default Cloud Build service account. According to the Tenable Research findings, attackers with edit permissions in Cloud Composer environments could exploit this process by injecting a malicious package, allowing them to escalate privileges and gain control over Cloud Build’s service account. This would grant access to critical GCP resources such as Cloud Build itself, Cloud Storage and Artifact Registry, demonstrating the risks of inherited cloud permissions.

ConfusedComposer is a variant of a vulnerability discovered by Tenable that was dubbed ConfusedFunction, it highlights the complexity and similarity of cloud services that eventually led to an exploitation variant.

ConfusedComposer highlights a broader security concern identified by Tenable as Jenga® Concept, the tendency for cloud providers to build services on top of one another, enabling security risks and weaknesses in one layer cascade into other services.

“When you play the Jenga® game, removing one block can make the whole tower unstable,” said Liv Matan, Senior Security Researcher at Tenable. “Cloud services work the same way. If one layer has risky default settings, then that risk can spread to others, making security breaches more likely to happen.”

Potential Impact of ConfusedComposer Exploitation:

If exploited, ConfusedComposer could allow attackers to:

  • Steal sensitive data from GCP services
  • Inject malicious code into CI/CD pipelines
  • Maintain persistent access through backdoors
  • Escalate privileges to potentially take full control of a victim’s GCP project

Google has addressed ConfusedComposer and no additional action is required.

Recommendations for Security Teams

While no user action is required to mitigate ConfusedComposer, Tenable recommends organizations to:

  • Follow the least privilege model to prevent unnecessary permission inheritance.
  • Map hidden dependencies between cloud services using tools like Jenganizer.
  • Regularly review logs to detect suspicious access patterns.

“The discovery of ConfusedComposer highlights the need for security teams to uncover hidden cloud interactions and enforce strict privilege controls. As cloud environments become more complex, it’s crucial to identify and address risks before attackers take advantage of them,” added Matan.

 

Tags: Tenable
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

TrendAI Becomes Part of Anthropic’s Project Glasswing

by DigitalCIO Bureau
June 5, 2026
0
TrendAI Becomes Part of Anthropic’s Project Glasswing

The collaboration will enhance efforts to detect and address software vulnerabilities through advanced AI capabilities. TrendAI, the enterprise AI security leader of Trend Micro, has announced its participation...

Read moreDetails

Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

by DigitalCIO Bureau
June 5, 2026
0
Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

Tata Technologies announced the launch of the 4th edition of its flagship engineering innovation hackathon, InnoVent-27. Building on its continued success, this year the initiative has been further...

Read moreDetails

Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

by DigitalCIO Bureau
June 4, 2026
0
Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

Combining advanced AI capabilities with deep manufacturing domain expertise, TCS will support Nokian Tyres in driving innovation and sustainable business outcomes Tata Consultancy Services (TCS) has entered into...

Read moreDetails

TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

by DigitalCIO Bureau
June 3, 2026
0
TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

TCS BaNCS and Quartz will support Euroclear Sweden’s move toward a unified Nordic securities ecosystem across the Finnish and Swedish financial markets. Tata Consultancy Services (TCS) today announced...

Read moreDetails

Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

by DigitalCIO Bureau
June 3, 2026
0
Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

A next-generation platform for building, deploying, and scaling AI across three core layers Hexaware Technologies has introduced new enhancements to Agentverse, its enterprise AI agent platform, focusing on...

Read moreDetails
Next Post
CrowdStrike Extends Its Elite MDR Services To Partners

CrowdStrike And Veeam Deliver Enhanced Data Security

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

State Sponsored Cyber Attacks — Shaping the Geo-Political Landscape?

UK and allies sanction Russian leader of LockBit cybercrime gang

May 8, 2024
EY and Microsoft announce global initiative to help clients scale AI enterprisewide value creation and move beyond experimentation

EY and Microsoft announce global initiative to help clients scale AI enterprisewide value creation and move beyond experimentation

May 25, 2026
SAP Hosts SIT Bengaluru 2024

SAP Hosts SIT Bengaluru 2024

December 10, 2024

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation E-books Fortinet Gartner Generative AI Google Cloud IBM India Infographics Infosys Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Salesforce Sophos Strategic Partnership Tata Consultancy Services TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?