Firebase is a technology platform tracked across 18 threat clusters and 23 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity June 30, 2026.
Firebase is a Google-backed platform for building and hosting web and mobile applications, offering services such as Firestore and Realtime Database, Authentication, Cloud Functions, Hosting, Storage, and Cloud Messaging. In cybersecurity, it is significant because misconfigurations, insecure hosting, or abuse of Firebase services can lead to data exposure and use as infrastructure for phishing or malware campaigns, making it important for defenders to understand its security model and access controls.
OrcaRouter Security Research released its AI Threat Report 2026, identifying prompt injection as the leading risk to large language model (LLM) applications, with a 340% increase in such attacks year-over-year. The…
A critical remote code execution (RCE) vulnerability has been identified in protobuf.js, a widely used JavaScript library for Protocol Buffers, affecting millions of applications. Discovered by Endor Labs, the flaw…
Bitdefender Labs has identified a widespread smishing campaign affecting drivers in at least 12 countries, including the United States, Canada, Australia, and the United Kingdom. Between December 2025 and April 2026,…
A vulnerability in Google's API key system has allowed unauthorized access to the Gemini AI platform from numerous Android applications. CloudSEK identified that existing API keys, meant for public services,…
Cerberus Anti-theft, a stalkerware application, has been available on Google Play since October 4, 2023, masquerading as a legitimate anti-theft tool. The app utilizes accessibility services and Google Firebase to…
A three-person development team in Mexico faces financial ruin after a stolen Google Cloud API key resulted in $82,314.44 in unauthorized charges within 48 hours. The key was compromised between February 11 and 12,…
A series of fraudulent apps named CallPhantom were discovered on Google Play, promising access to call histories for any phone number. Users were tricked into paying for subscriptions, only to receive fabricated data.…
Arsink RAT, a new Remote Access Trojan, is actively targeting Android devices to exfiltrate sensitive data and provide attackers with remote access. The malware spreads through platforms like Telegram and Discord,…
Recent research demonstrates that locally-hosted open-weight models can effectively replace cloud AI for security code reviews, addressing confidentiality concerns. The study found that a local model, running on…
Indian government entities were targeted in two cyber campaigns, Gopher Strike and Sheet Attack, linked to a threat actor in Pakistan. These campaigns utilized previously undocumented tradecraft and were identified by…