Cloud Run — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 4, 2025
Last Seen
July 16, 2026

Cloud Run is a technology platform tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity July 16, 2026.

Overview

Cloud Run is Google Cloud's fully managed, serverless platform for deploying and running stateless containers. It abstracts infrastructure and scales automatically with demand, making its security posture closely tied to container images, runtimes, and access controls—thus vulnerabilities in those layers can impact Cloud Run workloads.

Related Threat Clusters

  • Exposed Serverless Functions Present New Cybersecurity Risks

    Google's Mandiant has issued a warning about exposed serverless cloud functions, which are increasingly targeted by attackers due to their lack of authentication. These vulnerabilities allow access to sensitive…

    2 articles · Updated July 16, 2026
  • Google Denies Bug Bounty for Critical Kubernetes Flaw Still Unfixed

    Researcher Justin O'Leary discovered a significant vulnerability in Google Cloud's Kubernetes operator, allowing users to bypass Identity and Access Management (IAM) controls. Initially rated as high priority, Google…

    2 articles · Updated June 19, 2026
  • Critical React Flaw CVE-2025-55182 Exposes Major Security Risks

    A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…

    47 articles · Updated December 3, 2025

Recent Intelligence Reports

  • Google Mandiant warns of exposed serverless functions as attack vector — Feeds.Feedburner · July 16, 2026
  • Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed — Theregister · June 18, 2026
  • Responding to CVE-2025-55182 — Cloud.Google · December 4, 2025

CVSS v3.1 Breakdown