Sploitus New Exploits Target Google Cloud and Search Engine Vulnerabilities
Article Content
- •The 'gcp_scanner' tool evaluates GCP credential access levels.
- •The 'google_explorer' automates Google searches to find vulnerable sites.
- •Both tools are designed for exploitation and can lead to unauthorized access.
Two new exploits have emerged targeting Google Cloud Platform (GCP) and Google Search. The 'gcp_scanner' tool allows attackers to assess access levels of GCP credentials, including service account keys and OAuth2 tokens, potentially leading to unauthorized access. Meanwhile, the 'google_explorer' exploit automates searches on Google to identify vulnerable sites using specific 'dorks' and plugins. Both tools are designed for Linux environments, with 'gcp_scanner' being a standalone tool and 'google_explorer' requiring browser drivers. The impact of these tools could be significant, as they facilitate the discovery and exploitation of vulnerabilities in cloud and web applications. Security professionals are urged to assess their GCP configurations and monitor for potential misuse of these tools.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…