Skip to content
New Exploits Target Google Cloud and Search Engine Vulnerabilities

New Exploits Target Google Cloud and Search Engine Vulnerabilities

First seen 18 Sep 2026, 06:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 06:22 UTC
  • The 'gcp_scanner' tool evaluates GCP credential access levels.
  • The 'google_explorer' automates Google searches to find vulnerable sites.
  • Both tools are designed for exploitation and can lead to unauthorized access.

Two new exploits have emerged targeting Google Cloud Platform (GCP) and Google Search. The 'gcp_scanner' tool allows attackers to assess access levels of GCP credentials, including service account keys and OAuth2 tokens, potentially leading to unauthorized access. Meanwhile, the 'google_explorer' exploit automates searches on Google to identify vulnerable sites using specific 'dorks' and plugins. Both tools are designed for Linux environments, with 'gcp_scanner' being a standalone tool and 'google_explorer' requiring browser drivers. The impact of these tools could be significant, as they facilitate the discovery and exploitation of vulnerabilities in cloud and web applications. Security professionals are urged to assess their GCP configurations and monitor for potential misuse of these tools.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-17
gcp_scanner exploit released
The gcp_scanner tool was published, allowing assessment of GCP credential access levels.
Sploitus
2026-09-18
google_explorer exploit released
The google_explorer tool was released, enabling automated searches for vulnerabilities using Google.
Sploitus

More articles in this cluster (2)