Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Google Cloud Security

Google Cloud Security Vendor Cyber Rating & Cyber Score

google.com

With comprehensive cybersecurity solutions, organizations can address their tough security challenges with many of the same capabilities Google uses to keep more people and organizations safe online than anyone else in the world. Experience Mandiant frontline intelligence and expertise, a modern, intel-driven security operations platform, a secure-by-design cloud foundation, and more — all supercharged by AI.


GCS A.I CyberSecurity Scoring

GCS
Company Information
Website:https://cloud.google.com/security
Employees number:691
Number of followers:64,359
NAICS:541514
Industry Type:Computer and Network Security
Homepage:google.com
GCS Risk Score (AI oriented)
Between 0 and 549
logo
GCSComputer and Network Security
Updated:
27/08/2026
119/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
GCS Global Score (TPRM)
xxxx
logo
GCSComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

GCS
GCSCritical
Current Score
119C (CRITICAL)
01000
22 incidents
-38.07 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
117Before Incident
JULY 2026
100Before Incident
JUNE 2026
101Before Incident
Cyber Attack
11 Jun 2026GCS
Amazon Web Services and Google Cloud: Hackers Exploit AWS CloudTrail and Google Cloud Logging to Hide Attacks and Steal Logs

Threat Actors Exploit AWS and Google Cloud Logging to Evade Detection and Maintain Persistence

100After Incident
CRITICAL-1
GOOAMA1781166643
Threat Actors Exploit AWS and Google Cloud Logging to Evade Detection and Maintain Persistence Cybercriminals are increasingly targeting Amazon Web Services (AWS) CloudTrail and Google Cloud Logging to manipulate logs, evade detection, and maintain long-term access to victim environments. These attacks exploit fundamental trust in cloud logging systems, often going unnoticed by organizations that assume logs are inherently secure. The primary objectives of these attacks are defense evasion and continuous visibility. To evade detection, attackers disrupt or alter logging mechanisms, blinding security tools like SIEMs, SOAR, and CSPM platforms. Common techniques include: - Stopping logging (e.g., invoking `CloudTrail stop-logging` or disabling Google Cloud sinks). - Deleting storage destinations (e.g., removing S3 buckets or Google log buckets). - Deleting log routers (e.g., removing AWS trails or Google sinks). These actions create immediate visibility gaps, often preceding lateral movement or data exfiltration. More sophisticated methods impair forensic integrity without obvious disruption. Attackers may swap encryption keys (e.g., replacing AWS KMS keys or Google Cloud CMEK keys) and revoke access, rendering logs unreadable while still being written. Log poisoning is another risk adversaries can download, modify, and reupload JSON log files, corrupting audit trails and misleading investigations. While AWS offers CloudTrail log file integrity validation and Google provides log bucket locking, these protections are not universally enabled and can be bypassed if misconfigured. For continuous visibility, attackers create or modify log routing to send copies of logs to attacker-controlled destinations. On AWS, they can update trails to target external S3 buckets, while on Google Cloud, they can redirect sinks to external storage. This allows near real-time monitoring of privilege changes, resource creation, and data access, enabling stealthy reconnaissance and privilege escalation. The impact varies by technique: - High-impact, high-signal (e.g., stopping logging or log redirection) clearly indicates malicious intent. - Low-signal, high-impact (e.g., log deletion or encryption misuse) may appear as operational errors unless closely monitored. Defenders are advised to treat logging infrastructure as high-value assets, enforcing strict controls such as: - Restricting API calls for `update-trail`, `stop-logging`, and `logging.sinks.update`. - Enforcing least privilege on S3 and Cloud Storage. - Enabling CloudTrail log file integrity validation and Google log bucket locking. - Ensuring only logging service principals can write to canonical buckets. Detection strategies include: - Using immutably retained, provider-managed buckets (e.g., AWS Event History, Google’s Required/Default log buckets). - Alerting on modifications to trails, sinks, KMS/CMEK keys, or unexpected log destination updates. - Monitoring EventBridge or Cloud Audit Logs for suspicious configuration changes. These attacks underscore the critical need to secure cloud logging infrastructure, as control over logs equates to control over detection.
INCIDENT DETAILS -
TYPE
Cloud Security Incident
MOTIVATION
Defense evasionContinuous visibilityLateral movementData exfiltration
IMPACT
Data Compromised: Log integrity and audit trailsAWS CloudTrailGoogle Cloud LoggingSIEMsSOARCSPM platformsOperational Impact: Loss of visibility into cloud environments, impaired forensic investigations
DATA BREACH
Type Of Data Compromised: Log files and audit trailsSensitivity Of Data: High (log integrity critical for security investigations)Data Exfiltration: Possible via log redirection to attacker-controlled destinationsData Encryption: Possible via encryption key swapping or misuseJSON log files
MAY 2026
100Before Incident
Vulnerability
27 May 2026GCS
Google: MCP Toolbox Vulnerability Exposes Enterprise Database Systems

Critical Google MCP Toolbox Vulnerability Exposes Enterprise Databases to Unauthorized Access

100After Incident
CRITICAL0
GOO1780302559
Critical Google MCP Toolbox Vulnerability Exposes Enterprise Databases to Unauthorized Access A severe security flaw in Google’s MCP Toolbox for Databases, tracked as CVE-2026-9739 (CVSS 9.4), allows unauthenticated attackers to exploit DNS rebinding attacks and gain unauthorized command-level access to connected enterprise databases. The vulnerability affects organizations using the Server-Sent Events (SSE) transport mechanism in MCP specification v2024-11-05. The issue stems from a hardcoded `Access-Control-Allow-Origin: *` header inadvertently left in the SSE initialization handler, overriding security protections introduced during the toolbox’s beta phase. This misconfiguration, classified under CWE-942 (Permissive Cross-domain Policy with Untrusted Domains), enables attackers to bypass CORS protections by tricking Chrome browsers into treating malicious domains as trusted local resources. Once exploited, attackers can establish unauthorized SSE connections to the Toolbox interface and execute arbitrary commands against Cloud SQL, AlloyDB, and Spanner databases. The flaw requires no privileges, has a network-based attack vector, and poses high risks to confidentiality, integrity, and availability. Google acknowledged the issue on May 27, 2026, releasing a patch the following day via a GitHub advisory (issue #3053, PR #3054). While no proof-of-concept exploits or active attacks have been observed, the critical severity and broad enterprise exposure necessitate immediate action. Related vulnerabilities (CVE-2026-34742 in the Go MCP SDK and CVE-2026-35568 in the MCP Java SDK) highlight systemic weaknesses in MCP’s origin validation. Organizations are advised to disable SSE connections if unused, enforce strict CORS policies, restrict Toolbox endpoints to trusted networks, and audit AI agent pipelines for exposed instances.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Enterprise database access (Cloud SQL, AlloyDB, Spanner)Systems Affected: Google MCP Toolbox for Databases (SSE transport mechanism)Operational Impact: Unauthorized command execution, potential data breachesBrand Reputation Impact: High (Google MCP Toolbox)
DATA BREACH
Type Of Data Compromised: Enterprise database access (Cloud SQL, AlloyDB, Spanner)Sensitivity Of Data: High (enterprise databases)
MAY 2026
183Before Incident
Breach
24 May 2026GCS
Google Cloud: Everyone is navigating AI security in real time — even Google

Google Cloud API Key Exploitation and AI Security Challenges

100After Incident
CRITICAL-83
GOO1779669072
Google Cloud COO Highlights AI Security Challenges as Threats Evolve at Machine Speed At a recent Los Angeles event, Google Cloud COO Francis de Souza emphasized the urgent need for organizations to integrate security into AI adoption from the outset, warning that outdated defensive models are no longer sufficient. Speaking to the risks of "shadow AI" where employees use unvetted consumer tools de Souza stressed that AI strategies must be paired with robust data and security frameworks. He also highlighted the expanding attack surface, noting that threats now move at unprecedented speeds, with the average time between a breach and lateral movement dropping from eight hours to just 22 seconds. De Souza pointed to overlooked vulnerabilities, such as forgotten data repositories (e.g., old SharePoint servers) that AI agents can uncover, exposing sensitive information. To counter these risks, he advocated for AI-native defenses, where automated agents operate at machine speed under human oversight a shift he framed as a board-level priority. However, the industry faces a critical skills gap, with security teams struggling to keep pace with AI-driven vulnerabilities. Meanwhile, Google Cloud itself has faced scrutiny over security lapses. Recent reports revealed developers hit with five-figure bills after attackers exploited publicly exposed API keys originally meant for Google Maps that were later repurposed for Gemini access without clear disclosure. Victims, including Prentus CEO Rod Danan and Sydney-based developer Isuru Fonseka, saw charges surge to $10,000 and AUD $17,000, respectively, after Google’s automated systems raised their spending limits without explicit consent. While Google issued refunds, it maintained its policy of prioritizing service continuity over user-set budgets. Further investigations by security firm Aikido found that revoking compromised API keys doesn’t immediately halt attacks. Due to gradual propagation across Google’s infrastructure, attackers can exploit keys for up to 23 minutes post-deletion, exfiltrating data or cached conversations. Aikido researcher Joseph Leon noted that newer credential formats revoke in seconds, suggesting the delay is a matter of priority rather than technical limitation. The incidents underscore a disconnect between Google’s security prescriptions and its own platform’s adaptability.
INCIDENT DETAILS -
TYPE
API Key ExploitationData ExfiltrationUnauthorized Access
MOTIVATION
Financial GainData Theft
IMPACT
$10,000 (Prentus CEO Rod Danan)AUD $17,000 (Sydney-based developer Isuru Fonseka)Data Compromised: Cached conversations, sensitive dataGoogle Cloud services (e.g., Gemini)User accounts with exposed API keysOperational Impact: Unauthorized API usage, automated spending limit increasesBrand Reputation Impact: Negative scrutiny over security lapses and refund policies
DATA BREACH
Cached conversationsSensitive dataSensitivity Of Data: High (potential PII or proprietary data)
APRIL 2026
177Before Incident
Vulnerability
28 Apr 2026GCS
Google: Cyber Security News ®’s Post

Critical Gemini CLI Vulnerability Exposes CI/CD Pipelines to Remote Code Execution

173After Incident
CRITICAL-4
GOO1777350230
Critical Gemini CLI Vulnerability Exposes CI/CD Pipelines to Remote Code Execution A severe security flaw in the Gemini CLI specifically the @google/gemini-cli npm package and the google-github-actions/run-gemini-cli GitHub Action has been identified, enabling attackers to execute remote code in automated workflows. The vulnerability primarily affects headless environments, such as CI/CD pipelines, where the tool processes untrusted inputs like external pull requests or issue submissions. The issue stems from two key weaknesses: 1. Unsafe workspace trust handling – Misconfigurations in trust models can allow malicious payloads to bypass security controls. 2. Bypass of tool allowlisting under `--yolo` mode – A relaxed execution mode that disables safeguards, permitting unintended command execution. Systems are particularly at risk when processing external contributions in automated pipelines, where attackers could exploit these flaws to gain unauthorized access. Mitigation strategies include disabling unsafe execution modes, enforcing least-privilege access for runners and tokens, and validating inputs before execution. The discovery highlights broader risks in DevOps automation, where security gaps in tooling and configuration can expose critical infrastructure to exploitation. No active exploitation has been reported at this time.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: CI/CD pipelines, automated workflowsOperational Impact: Unauthorized access to critical infrastructure, potential data exfiltration or system compromiseBrand Reputation Impact: Potential reputational damage due to security flaws in DevOps tooling
APRIL 2026
178Before Incident
Vulnerability
20 Apr 2026GCS
gRPC and Google Cloud: 52M-Download protobuf.js Library Hit by RCE in Schema Handling

Critical RCE Vulnerability in protobuf.js Exposes Cloud and Microservice Systems

174After Incident
CRITICAL-4
GOOG-R1776771217
Critical RCE Vulnerability in protobuf.js Exposes Cloud and Microservice Systems Researchers at Endor Labs have uncovered a severe remote code execution (RCE) vulnerability in protobuf.js, a widely used JavaScript library with nearly 52 million weekly downloads. Tracked as GHSA-xq3m-2v4x-88gg and assigned a CVSS score of 9.4, the flaw stems from unsafe dynamic code generation in the library’s `Type.generateConstructor` function, which converts untrusted input into executable JavaScript. ### Attack Mechanism and Exploitation The vulnerability arises when protobuf.js processes malicious .proto or JSON files containing crafted "type names" that include executable JavaScript payloads. Since the library fails to sanitize these inputs, attackers can inject arbitrary code that executes when the schema is loaded even in automated or server-side workflows without direct user interaction. Exploitation is trivial once a poisoned file is processed, enabling threat actors to achieve full RCE, exfiltrate credentials, or pivot through internal networks. The flaw affects systems using gRPC, Firebase, and Google Cloud if they rely on protobuf.js and accept untrusted schema input. Multi-tenant platforms or gRPC reflection services are particularly at risk. ### Scope and Impact Unlike a supply-chain attack, the issue lies in how protobuf.js handles user-provided data. Researchers note this reflects a broader threat model "dev-tool-as-code-execution-primitive" where development tools inadvertently become attack vectors. While the library itself is legitimate (maintained by Google-affiliated developers), its widespread use in cloud and microservice architectures amplifies the risk. ### Affected Versions and Fix The vulnerability impacts: - protobuf.js 8.0.0 and earlier - 7.5.4 and earlier Endor Labs disclosed the flaw to maintainers on 2 March 2026, with confirmation on 9 March 2026. A patch was released in April 2026, introducing a one-line fix (`jsname = name.replace(/\W/g, "")`) to strip dangerous characters from input. Organizations are urged to update to 8.0.1 or 7.5.5 to mitigate the risk.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Credentials, internal network accessSystems Affected: Cloud and microservice systems using protobuf.js (gRPC, Firebase, Google Cloud)Operational Impact: Potential full system compromise, lateral movement in networks
DATA BREACH
CredentialsInternal network dataSensitivity Of Data: High (potential for full system access)Data Exfiltration: Possible.protoJSON
MARCH 2026
185Before Incident
Cyber Attack
20 Mar 2026GCS
Windsurf, Cursor, npm and Google: Hackers Use Fake Gemini npm Package to Steal Tokens From Claude, Cursor, and Other AI Tools

New Supply Chain Attack Targets AI Developers with Malicious npm Package

165After Incident
CRITICAL-20
ANYNPMWINGOO1775593675
New Supply Chain Attack Targets AI Developers with Malicious npm Package A sophisticated supply chain attack emerged on March 20, 2026, when a threat actor published a malicious npm package, gemini-ai-checker, under the account gemini-check. Marketed as a utility to verify Google Gemini AI tokens, the package contained hidden malware designed to steal credentials, files, and tokens from AI coding environments. The package’s README mimicked a legitimate JavaScript library, chai-await-async, though the two were unrelated a red flag many developers overlooked. Upon installation, the malware silently contacted a Vercel-hosted staging server (server-check-genimi.vercel.app) to download and execute a JavaScript payload directly in memory, evading traditional security tools. The attack was traced to OtterCookie, a JavaScript backdoor linked to the Contagious Interview campaign, attributed to North Korean (DPRK) threat actors. Microsoft documented a similar variant in March 2026, active since October 2025. The same actor maintained two additional malicious packages express-flowlimit and chai-extensions-extras sharing the same Vercel infrastructure. By publication, the three packages had been downloaded over 500 times combined, with gemini-ai-checker removed just before April 1, 2026, while the others remained active. This campaign uniquely targeted AI developer tools, including Cursor, Claude, Windsurf, PearAI, Gemini CLI, and Eigent AI, extracting API keys, conversation logs, and source code. The malware also stole browser credentials and cryptocurrency wallets, including MetaMask and Exodus. The infection mechanism was designed to evade detection. The package included 44 files and four dependencies, appearing legitimate with a SECURITY.md file. A hidden libconfig.js file split the command-and-control (C2) configuration into fragments, reassembled at runtime by libcaller.js to fetch the payload. The malware executed in memory using Function.constructor instead of eval to bypass static analysis. Once active, the payload deployed a four-module architecture, each running as a separate Node.js process connected to 216.126.237.71 on dedicated ports. Module 0 established remote access via Socket.IO, Module 1 targeted browser databases and cryptocurrency wallets, Module 2 scanned for sensitive files in AI tool directories, and Module 3 monitored the clipboard with a delayed startup to avoid sandbox detection. Defenders were advised to monitor outbound connections to Vercel and use Microsoft’s KQL queries to detect suspicious Node.js behavior. The incident underscored the risks of unverified npm packages and the need to treat AI tool directories with the same caution as sensitive system folders.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Espionage, Financial Gain, Credential Theft
IMPACT
Data Compromised: API keys, conversation logs, source code, browser credentials, cryptocurrency walletsSystems Affected: AI developer tools (Cursor, Claude, Windsurf, PearAI, Gemini CLI, Eigent AI)Operational Impact: Data exfiltration, unauthorized access to AI environmentsIdentity Theft Risk: HighPayment Information Risk: High (cryptocurrency wallets)
DATA BREACH
API keysConversation logsSource codeBrowser credentialsCryptocurrency wallet dataSensitivity Of Data: HighData Exfiltration: YesData Encryption: No (payload executed in memory)Personally Identifiable Information: Browser credentials, cryptocurrency wallet data
MARCH 2026
200Before Incident
Cyber Attack
08 Mar 2026GCS
GitHub, NPM, Google and AWS: 83% of Cloud Breaches Start with Identity. AI Agents are About to Make it Worse.

Google’s Cloud Threat Horizons Report: Accelerating Cyber Threats and Flawed Defenses

181After Incident
CRITICAL-19
GOOAMANPMGIT1773319158
Google’s Cloud Threat Horizons Report Reveals Accelerating Cyber Threats and Flawed Defenses Google’s H1 2026 Cloud Threat Horizons Report, compiled by the Google Threat Intelligence Group, Mandiant Incident Response, and the Office of the CISO, highlights a rapidly evolving threat landscape that outpaces traditional security measures. The report identifies three critical vulnerabilities in enterprise defenses: unchecked identity sprawl, weaponized AI tools, and collapsing exploitation windows all demanding a fundamental shift in security architecture. ### Identity Failures: The Unresolved Crisis Expands For years, stolen credentials and phishing have dominated breach vectors, yet organizations continue to overprovision access prioritizing operational convenience over security. Google’s data reveals that 83% of cloud intrusions in H2 2025 stemmed from identity compromise, but the real concern lies in where these failures occur. Two incidents illustrate the shift: - UNC4899 (North Korean actors) exploited unconstrained CI/CD service accounts in Kubernetes, bypassing human oversight entirely. - UNC6426 leveraged a compromised GitHub token to escalate to full AWS admin access within 72 hours, demonstrating how non-human identities service accounts, OIDC roles, and long-lived tokens now drive attacks. The proliferation of AI agents, which authenticate autonomously and traverse environments at machine speed, risks repeating these mistakes at an unprecedented scale. ### AI as an Attacker’s Reconnaissance Tool The QUIETVAULT credential stealer, embedded in a malicious NPM package, didn’t just exfiltrate tokens it hijacked the victim’s local LLM to scan for sensitive files (.env, .conf, .log) before extracting credentials. The attacker didn’t need to deploy new malware; the developer’s trusted AI-assisted environment became an automated reconnaissance engine, invisible to traditional endpoint detection. Most organizations lack visibility into LLM process execution, let alone policies to detect anomalous activity. ### Exploitation Windows Collapse to Days In H2 2025, threat actors deployed cryptocurrency miners within 48 hours of a critical CVE’s disclosure. Software-based initial access vectors surged from 2.9% to 44.5% of incidents in six months, shrinking the window between vulnerability disclosure and mass exploitation from weeks to days. Manual patching, access reviews, and incident triage are now obsolete Google’s automated forensic pipeline reduced cloud compromise investigations from days to under 60 minutes, proving that human-speed responses are no longer viable. ### The Case for AI-Native Security The report argues that bolting AI onto legacy security tools is insufficient. Instead, enterprises need AI-native security architectures designed for: - Identity governance that accounts for autonomous AI agents, not just human users. - Threat detection that treats LLM activity as a primary signal. - Automated response pipelines where human judgment intervenes only for critical decisions, not as a bottleneck. Adversaries already operate at machine speed, exploiting ungoverned identities and weaponizing AI. Organizations delaying this shift are making a present-tense risk decision one the data shows is already being exploited.
INCIDENT DETAILS -
TYPE
Identity CompromiseAI WeaponizationSoftware Exploitation
MOTIVATION
Financial Gain (Cryptocurrency Mining)Data ExfiltrationEspionage
IMPACT
CredentialsSensitive Files (.env, .conf, .log)Personally Identifiable InformationKubernetesAWSGitHubLLM EnvironmentsOperational Impact: Bypassed human oversight; automated reconnaissance and exploitationIdentity Theft Risk: High
DATA BREACH
CredentialsSensitive Configuration FilesLogsSensitivity Of Data: HighData Exfiltration: Yes.env.conf.logPersonally Identifiable Information: Yes
MARCH 2026
220Before Incident
Cyber Attack
06 Mar 2026GCS
Verizon, Google and Eclypsium: New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots

New Malware Strains Exploit Network Devices for DDoS and Crypto Mining

200After Incident
HIGH-20
VERGOOECL1773851169
New Malware Strains Exploit Network Devices for DDoS and Crypto Mining On March 6, 2026, security researchers uncovered two previously undetected malware strains CondiBot and Monaco targeting Linux-based routers, IoT devices, and enterprise network equipment. Both strains evaded major threat intelligence platforms, including VirusTotal and ThreatFox, until their discovery. CondiBot, a Mirai-based DDoS botnet, infects devices by cycling through multiple file transfer utilities (wget, curl, tftp, ftpget) to deliver its payload. Once executed, it disables reboot utilities, registers with a command-and-control (C2) server, and awaits attack commands. The malware includes 32 attack modules an expansion from earlier variants and actively kills competing botnets to monopolize system resources. A new internal identifier, "QTXBOT," suggests a possible fork or separate development group. Monaco, written in Go 1.24.0, brute-forces weak SSH credentials to deploy Monero cryptocurrency mining software on compromised servers, routers, and IoT devices. Unlike CondiBot, it focuses on stealthy resource exploitation rather than DDoS attacks. Researchers from Eclypsium noted that these campaigns reflect a broader trend: financially motivated threat actors are increasingly targeting network infrastructure, a tactic once dominated by nation-state groups. The 2025 Verizon Data Breach Investigation Report highlighted an 8x increase in exploits targeting network devices, with a median patching time of 30 days far slower than the zero-day exploit window. Google Threat Intelligence Group further reported that 25% of all zero-day exploits in 2025 targeted network and security systems. A critical challenge is the visibility gap in enterprise security. Most endpoint detection tools cannot monitor embedded firmware in network appliances, allowing attackers to operate undetected for extended periods. CondiBot’s persistence mechanisms including hardware watchdog manipulation make infections difficult to remove without physical intervention. The emergence of these strains underscores the growing threat to network infrastructure, where unpatched devices and weak credentials create prime targets for both DDoS and cryptojacking operations.
INCIDENT DETAILS -
TYPE
DDoSCryptojacking
MOTIVATION
Financial gainResource exploitation
IMPACT
Linux-based routersIoT devicesEnterprise network equipmentOperational Impact: Monopolization of system resources by malware
FEBRUARY 2026
210Before Incident
JANUARY 2026
219Before Incident
Cyber Attack
13 Jan 2026GCS
GLOBSEC and Google: Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts

Russian-Linked Cyber Espionage Campaign Expands OAuth and Phishing Tactics

200After Incident
CRITICAL-19
GOOGLO1787819408
Russian-Linked Cyber Espionage Campaign Expands OAuth and Phishing Tactics A sophisticated cyber espionage campaign linked to Russian threat actors including UNC6293, a subcluster of ICE RELIC (APT29/Cozy Bear/Midnight Blizzard) is escalating account-compromise operations by abusing legitimate authentication workflows. The campaign combines OAuth phishing, device-code attacks, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups to bypass multi-factor authentication (MFA) protections. ### Key Tactics and Infrastructure The attackers exploit trust in authentication processes rather than software vulnerabilities, tricking victims into authorizing attacker-controlled access. This method undermines MFA by convincing targets to complete legitimate logins before handing over tokens or OAuth permissions. Lure Domains and Social Engineering - foreignrelations[.]us and dosportal[.]app were identified as OAuth phishing lures, with historical WHOIS data linking them to the registrant email given956[@]2200freefonts[.]com, which also registered internationalaffairsportal[.]us and stateaffairs[.]us. - Archived content on foreignrelations[.]us referenced a Council on Foreign Relations article, while other domains reused web templates and meta tags to mimic trusted diplomatic and policy content. - Evilginx-style behavior was observed on stateaffairs[.]us subdomains between January 13 and February 2, 2026, redirecting users to legitimate U.S. Department of State sites to capture session credentials. Additional Threat Clusters - UNC7005, tracked separately due to weaker operational security, used Microsoft device-code phishing and targeted WhatsApp accounts via fake event invitations (e.g., a spoofed GLOBSEC Forum 2026 lure hosted on my-invite[.]org). - UNC5976 focused on Google-themed OAuth phishing, including drive[.]google[.]verify-drive[.]com, which mimicked Google Drive with a decoy login page. A shared favicon hash (c66f20f2e39eb2f6a0a4cdbe0d955e5f) linked multiple domains, aiding detection. ### Targets and Impact The campaign primarily targets academia, government, aerospace, defense, and think tanks across Europe and the U.S.. By blending polished decoy sites, legitimate redirects, and OAuth prompts, the attackers reduce the likelihood of detection before account access is compromised. ### Indicators of Compromise (IOCs) - IPs: 151.236.15[.]213, 185.158.250[.]155 - Domains: fllefolder[.]com, sharefolders[.]org, formshare[.]cloud, sharedfolders[.]org - Subdomains: drive[.]google[.]sharefolders[.]org, drive[.]google[.]formshare[.]cloud The campaign highlights the growing threat of adversary-in-the-middle (AitM) phishing frameworks, which exploit trust in identity services rather than technical flaws. Organizations are advised to monitor for unexpected OAuth consent requests, device-code prompts, and anomalous token usage to mitigate exposure.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Cyber espionage
DATA BREACH
Session credentialsAuthentication tokensPersonally identifiable informationSensitivity Of Data: High
JANUARY 2026
268Before Incident
Cyber Attack
01 Jan 2026GCS
ConnectWise, LogMeIn, Kaseya, O&O Software, WebEx, Arctic Wolf, Oracle and Google: ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

Cybersecurity Roundup: Major Threats and Disruptions in Early 2026

216After Incident
HIGH-52
ARCCONO&OLOGKASORAWEBGOO1784262481
Cybersecurity Roundup: Major Threats and Disruptions in Early 2026 A series of high-profile cyber threats and law enforcement actions have marked the first half of 2026, targeting individuals, businesses, and critical infrastructure across multiple regions. ### Phishing Campaigns Exploit RMM Tools and AI-Generated Lures A sustained phishing operation, SeasonalInvite, has been active since January 2026, abusing commercial Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&O Syspectr to compromise Windows and macOS users. The campaign leverages seasonal themes, distributing malicious links via phishing emails and poisoned search results. Researchers identified 959 eCard-themed domains and a traffic distribution system (TDS) using 2,658 gate pages to evade security scanners. The phishing pages appear to be AI-generated, suggesting threat actors used large language models (LLMs) to rapidly adapt their tactics. ### Chrome Sync Feature Abused for Surveillance A legitimate Chrome feature designed for cross-device synchronization has been weaponized by stalkers and cybercriminals. By briefly accessing a victim’s device, attackers can add a controlled Google account and enable sync, allowing them to monitor browsing history, bookmarks, and saved passwords in real time. The method requires no malware, making detection difficult. ### Spanish Police Dismantle €140M Cybercrime Network Authorities in Spain, in collaboration with international partners, disrupted a €140 million cybercrime operation involving fake investment platforms, CEO fraud, and adversary-in-the-middle (AitM) attacks. Four suspects were arrested two in Portugal, one in Spain, and one in Panama. The group used 800+ bank accounts and a network of "money mules" to launder funds, funneling stolen cryptocurrency through third-country accounts. ### UAT-11795 Deploys Starland RAT and WLDR Implant in U.S. and Europe A Russian-speaking threat actor, UAT-11795, has been targeting users in the U.S. and Europe since June 2025 with a Python-based remote access trojan (RAT) called Starland and a PowerShell-based C2 implant (WLDR agent). The campaign uses trojanized installers for popular software like MobaXterm, WebEx, Zoom, and DBeaver, delivering payloads via ClickFix lures. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine, enabling stealthy data exfiltration and further payload deployment. ### Ransomware Attack Encrypts Network in Under 24 Hours An unnamed ransomware group compromised an internet-facing IIS web server in June 2026, deploying a Rust-based ransomware strain dubbed Spirals within 24 hours. The attackers used an ASP.NET web shell for initial access, disabled endpoint security, dumped the Security Account Manager (SAM) hive, and spread laterally using PsExec. The ransom note threatened to publish stolen data after six days if demands were not met. ### Vidar Stealer and XMRig Miner Campaign Targets Global Victims A financially motivated campaign detected in April 2026 delivers Vidar stealer (targeting browser credentials, cookies, and crypto wallets) and XMRig cryptocurrency miner via malvertising. The malware, distributed through cracked software lures, uses the Factory-v3 malware-as-a-service (MaaS) framework. Operators monetize stolen data on criminal markets while generating passive income from hijacked CPU cycles. ### Fake GitHub Repositories Spread Windows Infostealer A Russian-speaking threat actor created 290+ fake GitHub repositories impersonating trusted vendors like Arctic Wolf to distribute a Windows infostealer with the same codebase as BoryptGrab-Lineage. The malware targets 41 cryptocurrency wallet paths and 19+ browsers, exfiltrating stolen data to a Russian-hosted C2 server. The campaign highlights the risks of brandjacking and supply chain attacks. ### Dutch Authorities Arrest Alleged Mastermind Behind 700-Person Scam Network A 46-year-old man with Israeli and Polish citizenship was arrested in the Netherlands for allegedly running a global investment fraud network employing 700+ scammers across 20 call centers. Victims were manipulated into depositing funds often in cryptocurrency into fake platforms, with scammers maintaining contact for months to build trust. The operation is linked to €140 million in losses. ### New Phishing Toolkits and MFA Bypass Techniques Emerge - Jalisco: An AI-powered device code phishing toolkit that provisions fresh OAuth codes in real time, bypassing time-based MFA defenses. - OmegaLord: A JavaScript-based credential harvester that impersonates a PDF reader and collects phone numbers alongside passwords to intercept MFA codes. ### U.S. and Allies Sanction Russian Cybercrime Groups The U.S., U.K., and Australia imposed sanctions in November 2025 on Media Land LLC, ML.Cloud LLC, and three Russian nationals Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova for cybercrimes causing $62+ million in losses. The Rewards for Justice (RFJ) program offers up to $10 million for information on their activities. ### Critical Vulnerabilities Added to CISA’s KEV Catalog CISA added two high-severity flaws to its Known Exploited Vulnerabilities (KEV) catalog: - CVE-2026-46817: An improper privilege management vulnerability in Oracle E-Business Suite. - KNX Protocol Connection Authorization Option 1: An overly restrictive account lockout mechanism with unknown exploitation details. ### Eastern European C2 Infrastructure Mapped A Hunt.io analysis uncovered 3,900+ threat-activity-enabling servers across 302 Eastern European providers, with Russia’s Media Land leading (1,277 IPs), followed by Tactical RMM (232) and Acunetix (173). The findings underscore the region’s role in hosting cybercriminal infrastructure. ### Malicious NuGet Packages Drop Surveillance Payloads Eleven malicious NuGet packages, masquerading as game utilities and productivity tools, were found delivering a Python-based infostealer ("pepesoft.exe") from GitHub and Hugging Face. The payload uses AWS-style key material for remote configuration, binds activations to hardware, and includes a BitTorrent fallback mechanism. ### Windows Bind Links Exploited to Bypass EDR Bitdefender researchers demonstrated three techniques File-Binding, Process-Binding, and Silo-Binding that abuse Windows’ bind links to evade EDR detection. While Microsoft rated the findings as low severity (requiring admin access), the methods highlight potential gaps in endpoint security. ### Key Takeaways - Phishing and RMM abuse remain dominant attack vectors, with AI-generated lures increasing in sophistication. - MFA bypass techniques (e.g., device code phishing, OAuth abuse) are evolving, reducing the effectiveness of traditional defenses. - Ransomware and infostealers continue to target businesses and individuals, with 24-hour encryption timelines becoming more common. - Law enforcement actions have disrupted major cybercrime networks, but threat actors rapidly adapt. - Supply chain risks persist, with fake repositories and trojanized software posing significant threats. The first half of 2026 has seen a surge in financially motivated cybercrime, state-linked activity, and novel evasion techniques, underscoring the need for robust detection and response strategies.
INCIDENT DETAILS -
TYPE
PhishingRansomwareInfostealerMalwareCybercrime NetworkSupply Chain AttackMFA Bypass
MOTIVATION
Financial GainSurveillanceData TheftCryptocurrency Mining
IMPACT
Financial Loss: €140M+ (cybercrime network) + $62M+ (sanctioned groups)Browser credentialsCookiesCrypto walletsBrowsing historyBookmarksSaved passwordsPersonally identifiable informationCryptocurrency wallet pathsWindowsmacOSIIS Web ServersLateral movement in networksEndpoint security disablementData exfiltrationBrandjacking (e.g., fake GitHub repositories impersonating Arctic Wolf)Regulatory violationsFines imposedIdentity Theft Risk: High (PII and credentials stolen)Payment Information Risk: High (crypto wallets and browser credentials targeted)
DATA BREACH
CredentialsPIICryptocurrency wallet dataBrowsing historyBrowser cookiesSensitivity Of Data: High (PII, financial data, credentials)Data Exfiltration: Yes (Vidar stealer, Starland RAT, WLDR implant)Data Encryption: Yes (Spirals ransomware, XMRig miner)Personally Identifiable Information: Yes (browser credentials, crypto wallets, phone numbers)
DECEMBER 2025
276Before Incident
Cyber Attack
26 Dec 2025GCS
Oracle Cloud, Azure and AWS: TeamPCP Turns Cloud Infrastructure into Crime Bots

TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation

256After Incident
CRITICAL-20
AMAORAMIC1770695748
TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation A threat actor known as TeamPCP (also operating under aliases like PCPcat and ShellForce) is conducting automated, worm-like attacks on misconfigured and exposed cloud management services, compromising at least 60,000 servers worldwide since late December. The group’s campaign primarily targets Azure (60% of attacks), AWS (37%), and Google and Oracle cloud environments, exploiting well-documented vulnerabilities and misconfigurations rather than developing new attack methods. TeamPCP’s operations involve scanning for exposed Docker APIs, Kubernetes clusters, Ray dashboards, and systems with leaked secrets (such as `.env` files). Once inside, the group deploys malicious Python and Shell scripts to install proxies, tunneling software, and persistence mechanisms, effectively converting compromised infrastructure into a self-propagating botnet. A key tool in their arsenal is the React2Shell vulnerability (CVE-2025-29927), which allows remote command execution and data exfiltration. The group monetizes its attacks through multiple revenue streams, including: - Cryptocurrency mining using hijacked compute resources. - Data theft and extortion, with stolen records including personal IDs, employment records, and résumés published on a leak site operated by an affiliate, ShellForce. - Selling access to compromised systems for use as proxies or command-and-control infrastructure. - Ransomware deployment, leveraging infected systems as launchpads for further attacks. Notably, TeamPCP has targeted JobsGO, a Vietnamese recruitment platform, exfiltrating over two million records containing sensitive personal and professional data. Most victims are located in South Korea, Canada, the U.S., Serbia, and the UAE, with stolen information often used for phishing, impersonation, or account takeovers. Despite its sophistication, TeamPCP’s techniques are not novel the group relies on automated exploitation of known vulnerabilities and recycled tooling. Security firm Flare warns that the threat actor’s strength lies in its large-scale automation, turning exposed cloud infrastructure into a distributed criminal ecosystem. The group also maintains a Telegram channel (launched in November, with ~700 members) for updates and reputation-building, though researchers suggest it may have operated under previous aliases. The campaign underscores the risks of unsecured cloud control planes, leaked credentials, and poor access controls, as TeamPCP continues to industrialize existing attack vectors with alarming efficiency.
INCIDENT DETAILS -
TYPE
Cloud Misconfiguration ExploitationBotnetData TheftRansomware
MOTIVATION
Financial gainData extortionCryptocurrency miningSelling access to compromised systems
IMPACT
Data Compromised: Over two million records (personal IDs, employment records, résumés)Systems Affected: 60,000+ servers worldwideOperational Impact: Compromised infrastructure converted into a botnet for further attacksIdentity Theft Risk: High (personal and professional data used for phishing, impersonation, or account takeovers)
DATA BREACH
Personal IDsEmployment recordsRésumésNumber Of Records Exposed: Over two millionSensitivity Of Data: High (personally identifiable and professional information)
NOVEMBER 2025
410Before Incident
Breach
25 Nov 2025GCS
Google (Gmail users)

Aggregated Credential Leak from Infostealer Malware (Misreported as '183 Million Gmail Breach')

267After Incident
HIGH-143
GOO2212622112625
A dataset containing 183 million Gmail credentials was publicly disclosed, but it was not the result of a new breach of Google’s systems. Instead, the credentials were aggregated over time via infostealer malware infecting users' devices, harvesting stored passwords from browsers, and active logins. The dataset included unique email-password pairs along with the domains where they were used, compiled from criminal data-sharing channels (primarily Telegram). While most credentials were stale or from legacy breaches, a subset represented newly stolen data from ongoing infections.The incident highlights a persistent, automated ecosystem where credentials are continuously exfiltrated, traded, and weaponized for credential-stuffing attacks. Attackers exploit password reuse across services, targeting corporate portals, VPNs, and cloud systems. Though Google’s infrastructure remained uncompromised, the exposure underscores systemic risks from end-user endpoint infections and third-party breaches. The lack of real-time monitoring leaves organizations vulnerable to automated attacks leveraging fresh credential dumps before manual remediation cycles can respond.The case emphasizes the need for continuous password monitoring to detect and neutralize exposed credentials in real time, rather than relying on periodic scans or reactive measures triggered by headlines. The aggregated data, while not a direct breach, fuels ongoing attack campaigns against both personal and enterprise accounts.
INCIDENT DETAILS -
TYPE
Credential TheftData AggregationMisinformation
MOTIVATION
Financial GainCredential StuffingFraudAccount Takeover
IMPACT
183 million credentials (email:password pairs with domains)Legacy breach dataFresh infostealer logsIncreased risk of credential-stuffing attacksPotential account takeovers across services (corporate/personal)Reputational harm from misreportingPotential user panic due to misleading headlinesGoogle's denial clarified no breach, but misreporting caused confusionHighlighted broader industry issue of credential theftHigh (due to credential reuse across services)
DATA BREACH
Email:password pairsDomain associationsBrowser-stored credentialsNumber Of Records Exposed: 183 millionModerate to High (depends on credential reuse and service access)Via infostealer malware from endpointsEmail addressesPasswords
NOVEMBER 2025
425Before Incident
Cyber Attack
01 Nov 2025GCS
OpenClaw, Notepad++, Hikvision, Apache Syncope, Foxit, TP-Link, Cisco, Google Chrome and Arista NG Firewall: ⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More

Cybersecurity Roundup: Trust Abuse, AI Risks, and Supply Chain Attacks Dominate Threat Landscape

405After Incident
CRITICAL-20
TP-HIKFOXGOOREVARITHEOPECIS1770645410
Cybersecurity Roundup: Trust Abuse, AI Risks, and Supply Chain Attacks Dominate Threat Landscape This week’s cybersecurity developments highlight a growing trend: attackers are increasingly exploiting trusted systems AI platforms, software updates, messaging apps, and open-source ecosystems to bypass security controls. Below are the key incidents and trends shaping the threat landscape. ### AI and Open-Source Ecosystems Under Siege OpenClaw, an open-source AI agent framework, has partnered with Google’s VirusTotal to scan uploaded "skills" (AI extensions) for malware, following discoveries of malicious components in its ClawHub marketplace. Researchers warn that AI agents’ broad permissions, persistent memory, and user-controlled configurations create risks like prompt injection, data exfiltration, and supply chain attacks. Trend Micro reported threat actors on Exploit.in discussing OpenClaw for botnet operations, while Veracode noted a surge in typosquatted "claw" packages on npm and PyPI from zero in early 2026 to over 1,000 by February. Meanwhile, MoltBook, an AI-driven social platform built on OpenClaw, faces scrutiny after Simula Research Laboratory identified 506 prompt injection attacks, social engineering exploits, and unregulated cryptocurrency activity comprising 19.3% of its content. The platform’s autonomous AI agents, which interact without human oversight, raise concerns about data privacy and manipulation risks. Security firm Pillar Security detected active scanning of exposed OpenClaw gateways (port 18789), with attackers bypassing AI layers to target the WebSocket API directly for authentication bypasses and command execution. Censys identified 21,639 exposed OpenClaw instances as of January 2026, underscoring the framework’s outdated trust model lacking encryption-at-rest and containerization. ### Supply Chain Attacks: Trusted Updates as Malware Vectors A sophisticated supply chain attack targeted Notepad++ between June and December 2025, where threat actors redirected its WinGUp updater to malicious servers. Despite losing access to a compromised hosting provider in September, attackers reused stolen credentials to maintain control until December. The campaign, attributed to Lotus Blossom, exploited weak update verification in older Notepad++ versions, demonstrating how legitimate domains can become malware distribution hubs. Similarly, Docker’s AI assistant (Ask Gordon) was found vulnerable to remote code execution (RCE) via DockerDash, a flaw in its Model Context Protocol (MCP) Gateway. Attackers could embed malicious instructions in Docker image metadata, which the AI assistant executed without validation. Docker patched the issue in version 4.50.0 (November 2025). ### State-Sponsored Threats and High-Profile Targets Germany’s BfV and BSI issued a joint advisory warning of state-sponsored phishing attacks via Signal, exploiting the app’s PIN and device-linking features to hijack accounts. Targets included high-ranking officials, military personnel, diplomats, and journalists across Germany and Europe. In Ukraine, the government implemented a Starlink terminal verification system after confirming Russian forces were using the technology on attack drones. Only registered devices are now permitted to operate in the country. ### DDoS, Botnets, and Emerging Attack Techniques The AISURU/Kimwolf botnet set a record with a 31.4 Tbps DDoS attack in November 2025, lasting just 35 seconds. Cloudflare mitigated the attack, which was part of a broader campaign ("The Night Before Christmas") starting in December. Overall, DDoS attacks surged 121% in 2025, averaging 5,376 mitigated attacks per hour. Researchers also uncovered 54 malicious npm packages using EtherHiding, a technique leveraging Ethereum smart contracts to fetch C2 servers, complicating takedown efforts. The malware targets Windows systems with 5+ CPUs, employing sandbox evasion, COM hijacking, and system profiling. ### Linux Threats and Post-Exploitation Frameworks Cyble discovered ShadowHS, a fileless Linux post-exploitation framework that runs entirely in memory, prioritizing stealth and long-term control. The framework includes modules for credential access, lateral movement, privilege escalation, and data exfiltration, with aggressive defensive tooling enumeration to avoid detection. ### Ransomware, Dark Markets, and Legal Actions - INC Ransomware suffered a setback after Cyber Centaurs breached its backup server, helping 12 victims recover data. The group, active since 2023, had listed over 100 victims on its leak site. - Rui-Siang Lin, administrator of the Incognito Market darknet drug marketplace, was sentenced to 30 years in prison for facilitating $105 million in narcotics sales to over 400,000 users. - Xinbi, a Telegram-based illicit marketplace, processed $17.9 billion in transactions, outlasting competitors like Haowang and Tudou Guarantee, which saw declines of 100% and 74%, respectively. ### Critical Vulnerabilities and Exploits Notable CVEs disclosed this week include: - CVE-2026-25049 (n8n) - CVE-2026-0709 (Hikvision Wireless Access Point) - CVE-2026-23795 (Apache Syncope) - CVE-2026-1591/1592 (Foxit PDF Editor Cloud) - CVE-2026-24512 (ingress-nginx) - Multiple CVEs in Django, Google Chrome, Cisco, TP-Link, F5 BIG-IP, and Arista NG Firewall Additionally, XBOW uncovered two Insecure Direct Object Reference (IDOR) flaws in Spree (CVE-2026-22588/22589), allowing unauthorized access to user address data. ### Microsoft’s AI Backdoor Scanner Microsoft developed a scanner to detect hidden backdoors in open-weight AI models, addressing risks for enterprises relying on third-party large language models (LLMs). The tool identifies three key indicators: 1. Attention shifts when a hidden trigger is present. 2. Leakage of poisoned training data. 3. Partial triggers still activating malicious responses. The scanner extracts memorized content from models and ranks suspicious substrings as potential triggers. ### Conclusion This week’s incidents underscore a shift in attacker tactics exploiting trust in ecosystems, AI workflows, and supply chains rather than relying on traditional malware. As threats evolve, organizations must monitor integrations, verify updates, and secure AI deployments to mitigate risks from both state-sponsored actors and cybercriminals.
INCIDENT DETAILS -
TYPE
Supply Chain AttackAI ExploitationDDoSRansomwarePhishingMalwarePost-Exploitation Framework
MOTIVATION
Financial GainEspionageData ExfiltrationBotnet OperationsRansomwareDrug TraffickingState-Sponsored Surveillance
IMPACT
AI Agent ConfigurationsUser Data on MoltBookCredentialsSystem ProfilesPersonally Identifiable Information (PII)Payment InformationOpenClaw AI FrameworkNotepad++Docker AI AssistantSignal Messaging AppStarlink TerminalsLinux Systems (ShadowHS)Spree E-Commerce PlatformUnauthorized Command ExecutionData ExfiltrationBotnet OperationsAI Agent ManipulationDDoS DisruptionsMoltBook (AI-Driven Social Platform)Notepad++DockerOpenClawRegulatory Violations (GDPR, etc.)Fines for Data BreachesIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
AI Agent ConfigurationsUser DataCredentialsPIIPayment InformationDrug Trafficking RecordsSensitivity Of Data: HighYes (OpenClaw, ShadowHS, INC Ransomware)Yes (Ransomware)No (OpenClaw, ShadowHS)Personally Identifiable Information: Yes
OCTOBER 2025
488Before Incident
Breach
26 Oct 2025GCS
Google

Prolonged Insider Breach at Google Involving Play Store Infrastructure Data Exfiltration

424After Incident
HIGH-64
GOO5092350102625
Google suffered a prolonged insider breach orchestrated by a contractor with privileged access to sensitive systems. Over several weeks, the contractor unauthorizedly captured nearly 2,000 screenshots and exfiltrated critical internal files, including proprietary details on the Play Store infrastructure and its security guardrails designed to prevent malicious software distribution. The stolen data was transmitted to an external party, exposing vulnerabilities in one of Google’s core revenue drivers. The breach, driven by potential financial incentives or coercion, underscores risks tied to third-party access and insider threats. While Google initiated forensic investigations, notified authorities, and is auditing contractor vetting processes, the incident raises concerns about supply chain security, regulatory compliance, and trust erosion in its app ecosystem. Though no direct user data compromise was confirmed, the exposure of security protocols could enable adversaries to exploit app vulnerabilities or launch sophisticated attacks. The breach has triggered internal policy reviews, including stricter access controls, AI-driven anomaly detection, and multi-factor authentication for contractors.
INCIDENT DETAILS -
TYPE
insider threatdata exfiltrationunauthorized access
MOTIVATION
financial incentives (possible)external coercion (possible)
IMPACT
Play Store infrastructure detailssecurity protocolsproprietary insights into app distribution mechanismsscreenshots (~2,000)Google Play Store ecosysteminternal systems with sensitive datainternal audit of contractor vetting processesenhanced access controls implementationforensic investigationpotential erosion of trust in Play Store securityregulatory scrutinyinvestor confidence fluctuations
DATA BREACH
proprietary business informationsecurity protocolsinternal documentationscreenshotsSensitivity Of Data: high (internal infrastructure and security details)documentsscreenshotsproprietary files
SEPTEMBER 2025
543Before Incident
Breach
08 Sep 2025GCS
Google

Sophisticated Phishing Attack on Google Leading to Data Exposure of Multiple Companies

479After Incident
CRITICAL-64
GOO1162311090825
A sophisticated phishing attack targeted Google earlier this year, orchestrated by the hacking group ShinyHunters. The attackers tricked a Google employee into downloading malware via a deceptive email, granting them unauthorized access to the company’s internal systems. This breach led to a raid on Google’s Salesforce database, exposing sensitive corporate data belonging to high-profile clients, including Cisco, Louis Vuitton, and Adidas. While Google confirmed that regular Gmail user data remained uncompromised, the incident highlighted the escalating threat of credential-based attacks exploiting weak authentication measures. The breach underscored vulnerabilities in single-factor authentication, as the hackers leveraged legitimate employee credentials to infiltrate systems. The stolen data included proprietary business information, though the full scope of the leak—such as whether customer or financial records were exposed—was not publicly detailed. The attack demonstrated the growing sophistication of phishing tactics, compounded by the potential for AI-driven social engineering in future cyber threats. Security experts, including Damien Fortune (CEO of Syntriqs), emphasized the critical need for multi-factor authentication (MFA) to mitigate such risks, noting that attackers exploit gaps where legacy security protocols fail to adapt to evolving threats. The breach served as a stark reminder of how even tech giants remain vulnerable to human-error-driven cyber intrusions, with cascading consequences for partner organizations.
INCIDENT DETAILS -
TYPE
phishingmalwaredata breachcredential theft
MOTIVATION
financial gaindata theftcorporate espionage
IMPACT
corporate data from Salesforce databaseinformation from Cisco, Louis Vuitton, Adidas, and other companiesSalesforce database accessed via Google employee credentialspotential reputational damage to Google and affected companies (Cisco, Louis Vuitton, Adidas, etc.)eroded trust in Google's security measures
DATA BREACH
corporate databusiness information from Salesforce databasehigh (corporate-sensitive information)
JUNE 2025
535Before Incident
Vulnerability
16 Jun 2025GCS
Google

Google Chrome Zero-Day Vulnerability (CVE-2025-13223) in V8 JavaScript Engine

530After Incident
MEDIUM-5
GOO0402404111925
Google recently addressed a critical zero-day vulnerability (CVE-2025-13223) in its Chrome browser’s V8 JavaScript engine, marking the third such incident in recent months. The flaw, rated 'high' with a CVSS score of 8.8, was actively exploited in the wild before an emergency out-of-band patch was released on Monday. Discovered by Clément Lecigne of Google’s Threat Analysis Group (TAG), the vulnerability posed a significant risk, potentially allowing attackers to execute arbitrary code, compromise user data, or escalate privileges on affected systems. While no specific data breaches or direct financial losses were reported, the exploitation of such a high-severity flaw in a widely used browser like Chrome could have led to large-scale attacks, including phishing, malware distribution, or unauthorized access to sensitive user information. The proactive patching mitigated immediate risks, but the incident underscores the persistent threats posed by zero-day exploits in widely deployed software, which can undermine user trust and expose millions to cyber threats if left unaddressed.
INCIDENT DETAILS -
TYPE
Zero-day vulnerability
IMPACT
Google Chrome browser (V8 JavaScript engine)Brand Reputation Impact: Potential reputational risk due to repeated zero-day exploits
MAY 2025
532Before Incident
Vulnerability
01 May 2025GCS
Google Cloud

Cloud Security Issues in Google Cloud and AWS

528After Incident
LOW-4
GOO1046050625
In a comprehensive analysis of nearly five million internet-exposed assets, Google Cloud-hosted services showed 38% of assets with at least one security issue, more than double AWS’s 15% rate. Moreover, 5.35% of Google Cloud assets contained vulnerabilities deemed easy to exploit by attackers, driven by both misconfigurations and known software flaws. Although no widespread data theft or severe breaches have been reported to date, this high exposure rate leaves customer workloads susceptible to unauthorized access, potential data exposure, and service disruptions. Critical issues, while less common at 0.04%, combined with easily exploitable vulnerabilities could allow attackers to pivot through cloud environments, potentially undermining trust and disrupting business operations. Left unaddressed, these vulnerabilities may result in unexpected downtime, compliance violations, and reputational harm as security incidents attract media attention and scrutiny from regulatory bodies. The complexity of multi-cloud deployments further exacerbates the challenge, with overlooked assets and shadow IT creating additional attack surface. Security teams must prioritize continuous monitoring, automated patch management, and seedless discovery to identify and remediate misconfigurations and software flaws before they can be weaponized by adversaries.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationMisconfiguration
IMPACT
Google CloudAWSUnexpected DowntimeService DisruptionsBusiness Operations DisruptionsReputational HarmCompliance Violations
JANUARY 2025
533Before Incident
Cyber Attack
01 Jan 2025GCS
No specific organizations identified: How to Maximize DDoS Readiness with Proactive Protection Strategies

Rise of Terabyte-Scale DDoS Attacks in 2025

513After Incident
CRITICAL-20
GOO1771959630
Rise of Terabyte-Scale DDoS Attacks in 2025 Puts Businesses at Risk In 2025, Distributed Denial of Service (DDoS) attacks have escalated dramatically, shifting from gigabyte-scale disruptions to terabyte-level assaults that threaten organizations of all sizes. These attacks, which overwhelm digital infrastructure by flooding networks with malicious traffic, have become one of the most challenging cloud security threats to detect and mitigate. Small businesses face the same risks as large enterprises but often lack the resources to defend against them effectively. The evolution of DDoS tactics has been accelerated by AI-driven tools capable of orchestrating hyper-volumetric attacks in real time. These systems automate vulnerability discovery and coordinate massive botnets, making attacks more adaptive and efficient. To counter this growing threat, cybersecurity experts recommend a multi-layered defense strategy. Key Defense Measures: - Risk Assessment: Organizations should map public-facing assets, prioritize critical workloads, and conduct vulnerability scans to identify misconfigurations. Establishing baseline traffic patterns helps detect anomalies early. - Proactive Hardening: Reducing the attack surface by closing unused ports, implementing DNSSEC for cryptographic authentication, and using anycast routing to distribute traffic. Intelligent traffic controls, such as rate limiting and egress access lists, help filter malicious requests before they reach core systems. - Threat Intelligence: Integrating global IP reputation feeds and botnet activity tracking enables automatic blocking of known malicious sources, reducing the load on downstream defenses. - Response Infrastructure: A cross-functional team with defined roles ensures swift action during attacks. Hybrid defense architectures combining on-premises detection with cloud-based scrubbing provide both precision and scalability. Machine learning models enhance detection of sophisticated Layer 7 attacks that mimic legitimate traffic. - Monitoring & Validation: Real-time dashboards and simulated attack drills improve threat detection and response times. Automated playbooks enable sub-minute mitigation, while continuous remediation keeps defenses updated. - Ongoing Optimization: Post-incident reviews refine security policies, while DevSecOps practices integrate threat detection earlier in development. Regular vendor-agnostic audits ensure solutions remain effective, and AI-driven training improves detection accuracy over time. The shift to terabyte-scale DDoS attacks underscores the need for proactive, adaptive defenses. While no single tactic guarantees protection, a comprehensive approach combining risk assessment, hardening, real-time monitoring, and continuous optimization significantly reduces exposure and maintains operational stability.
INCIDENT DETAILS -
TYPE
DDoS
IMPACT
Systems Affected: Digital infrastructure, public-facing assets, critical workloadsOperational Impact: Overwhelmed networks, potential service disruptions
AUGUST 2024
699Before Incident
Breach
01 Aug 2024GCS
Google (via Salesforce third-party breach)

Major Third-Party Breach Exposes Billions of Gmail Users to Cyberattacks via Salesforce Cloud Platform

508After Incident
HIGH-191
GOO913090225
Google issued an urgent warning after a major third-party breach in Salesforce’s cloud platform exposed billions of Gmail users to cyberattacks. The breach, linked to the threat group ShinyHunters (UNC6040), involved social engineering (vishing)—hackers impersonated IT support to steal login credentials, leading to multiple successful intrusions by August 2024. Initially dismissed as 'basic business data,' the stolen information is now being weaponized for extortion and potential data leaks via a planned Data Leak Site (DLS). Attackers primarily targeted English-speaking employees of global organizations, exploiting dangling Cloud Storage buckets to hijack deleted bucket names, inject malware, or steal customer data.Google confirmed its own systems remained secure but warned of escalating risks, including account takeovers, phishing, and credential stuffing attacks affecting ~2.5 billion Gmail/Google Cloud users. While no direct financial or large-scale data theft was confirmed, the breach compromised user trust, heightened phishing risks, and exposed vulnerabilities in third-party integrations. Google notified affected users (Aug. 8) and urged 2FA adoption, password updates, and vigilance against suspicious links—though only ~33% of users regularly change passwords, leaving many exposed to follow-up attacks.
INCIDENT DETAILS -
TYPE
Data BreachSocial EngineeringCredential StuffingDangling Bucket Attack
MOTIVATION
Data ExfiltrationExtortionFinancial GainEscalation via Data Leak Site (DLS)
IMPACT
Business Data (initially 'basic and publicly available')Login CredentialsPotential Customer Data (via dangling buckets)Gmail AccountsGoogle Cloud Storage BucketsIncreased Phishing/Social Engineering RisksHeightened Monitoring RequirementsBrand Reputation Impact: High (Urgent warning issued to 2.5B users; trust in platform security questioned)Identity Theft Risk: High (Stolen credentials enable account takeovers)
DATA BREACH
Business DataLogin CredentialsPotentially Sensitive Customer Data (via dangling buckets)Number Of Records Exposed: Billions (exact number unspecified)Low (initially 'publicly available')High (credentials enable account takeovers)Data Exfiltration: Yes (by ShinyHunters/UNC6040)Personally Identifiable Information: Potential (via credential reuse)
JULY 2024
702Before Incident
Vulnerability
01 Jul 2024GCS
Google

Google Vulnerability Rewards Program (VRP) Study: Impact of Increased Bug Bounty Payouts on Vulnerability Reporting Quality and Quantity

698After Incident
CRITICAL-4
GOO3062030100725
Google’s Vulnerability Rewards Program (VRP) faced inefficiencies due to a flood of low-value bug reports, diverting security team resources from critical threats. Before July 2024, the program struggled with a high volume of low-severity submissions, straining triage and remediation efforts. While the program aimed to uncover high-impact vulnerabilities, the lack of targeted incentives led to an imbalance—skilled researchers prioritized easier, lower-tier bugs, and new contributors often submitted minimal or irrelevant findings. After restructuring payouts in July 2024—with up to a 200% increase for Tier 0 (most severe) vulnerabilities—Google observed a tripling of critical bug reports, but the shift also revealed systemic risks. The delay in addressing this imbalance had already allowed potential high-severity vulnerabilities (e.g., zero-days, authentication bypasses, or data exfiltration paths) to remain undetected longer than necessary. Competitors or malicious actors could have exploited these gaps, leading to unauthorized access, data breaches, or systemic compromises had the program not adapted. The initial misalignment in rewards effectively masked critical risks, leaving Google exposed to attacks that could have escalated to organizational disruption or reputational damage if unmitigated.
INCIDENT DETAILS -
TYPE
Bug Bounty Program AnalysisVulnerability Research Study
MOTIVATION
Financial Incentives (Bug Bounty Payouts)Research RecognitionCompetitive Advantage for Researchers
IMPACT
Increased triage workload for low-value submissionsResource allocation challenges for security teamsCompetition for skilled researchers among programsPositive: Improved vulnerability detectionPotential negative: Delays in triage or communication could harm researcher trust
AUGUST 2023
708Before Incident
Cyber Attack
01 Aug 2023GCS
Google

Hackers Threaten to Leak Google Databases Unless Employees Are Fired

687After Incident
HIGH-21
GOO905090225
A hacking collective identifying itself as Scattered LapSus Hunters—a coalition of members from Scattered Spider, LapSus$, and ShinyHunters—has threatened to leak Google’s internal databases unless the company terminates two employees: Austin Larsen and Charles Carmakal, both part of Google’s Threat Intelligence Group. The group also demanded Google halt its investigations into their network. While no direct evidence of a breach into Google’s systems was provided, the threat follows a confirmed incident in August 2023, where ShinyHunters (a subgroup within the collective) exfiltrated data from Salesforce, a third-party vendor used by Google. The attack appears to be a targeted extortion attempt, leveraging reputational pressure and potential operational disruption. Although no Google-owned data has been confirmed as compromised, the threat exploits prior third-party vulnerabilities to coerce compliance. The involvement of Google Threat Intelligence Group—a team focused on countering cyber threats—suggests the attackers aim to undermine Google’s defensive capabilities while exploiting media exposure for leverage. The lack of immediate data leaks or system infiltrations keeps the direct impact speculative, but the reputational risk and operational strain (e.g., potential internal investigations, PR fallout) remain significant.
INCIDENT DETAILS -
TYPE
threatextortionpotential data breach
MOTIVATION
extortiondisruption of investigationsretaliation
IMPACT
Brand Reputation Impact: potential (due to public threat and media coverage)
JULY 2022
755Before Incident
Breach
24 Jul 2022GCS
Google

Google Salesforce Database Breach Leading to Phishing and Vishing Attacks

694After Incident
HIGH-61
GOO21105921090425
Google disclosed a data breach involving a Salesforce database used internally to manage potential advertisers. The breach was executed by the hacker group ShinyHunters, who impersonated an IT help desk employee to deploy malware and extract business contact information (e.g., company and customer names). While no personal Gmail credentials or sensitive consumer data were exposed, the stolen data fueled a surge in highly targeted phishing and vishing (voice phishing) attacks, accounting for 37% of successful account takeovers across Google platforms. The attackers also compromised OAuth tokens for the Drift Email integration, prompting Google to revoke access and disable the Salesforce-Gmail connection to prevent further spread. Though the breach was contained to Salesforce and did not directly compromise Google Workspace or Alphabet, the leaked business data enabled sophisticated social engineering scams, increasing risks for users. Google advised password updates, non-SMS 2FA, and migration to passkeys (biometric authentication) as mitigation. No timeline for further disclosures was provided, but analysts anticipate ongoing attacks leveraging the exposed data.
INCIDENT DETAILS -
TYPE
Data BreachPhishing AttackSocial Engineering
MOTIVATION
Financial Gain (Phishing/Scams)Data Exfiltration for ResaleDisruption
IMPACT
Business Contact Information (Company Names, Customer Names)Salesforce Database (Advertiser Management)Drift Email IntegrationOAuth TokensTemporary Suspension of Gmail-Salesforce IntegrationsRevocation of OAuth TokensIncreased Phishing Risks for 2.5B Gmail UsersErosion of Trust in Google Workspace SecurityLow (No PII or Passwords Compromised)
DATA BREACH
Business Contact Information (Non-Sensitive)Sensitivity Of Data: Low (No PII, Passwords, or Financial Data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for GCS ?
?
What was GCS's A.I Rankiteo Cyber Score in July 2026 ?
?
What was GCS's A.I Rankiteo Cyber Score in June 2026 ?
?
What was GCS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was GCS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was GCS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was GCS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was GCS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was GCS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was GCS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was GCS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was GCS's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on GCS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with GCS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view GCS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?