Our Google Cloud VRP researchers don't miss! 🔥 Check out @terminatorLM's latest Looker research uncovering 9 novel cross-tenant vulns in Looker.
See how it was done: 👇
🫣LeakyLooker: 1 Cross-tenant vulnerability? How about 9? (1/10)🧵
I’m incredibly proud to share LeakyLooker. I discovered 9 novel cross-tenant vulnerabilities in Google Cloud’s Looker Studio that broke fundamental design assumptions.
Here is how I broke tenant isolation: 👇
Disclosure (9/10)🧵
Huge thanks to the Google VRP team. They handled these reports professionally and moved quickly to remediate them all. All issues are now fully patched. No customer action is required.
🎄🎄🎄
I went to a meetup last night about cloud attacks and watched a talk by @terminatorLM about GCP, and it was SO GOOD!!
I came home with so many ideas and so much motivation.
Turns out it’s also on YouTube! please watch it, no matter which cloud you’re into🤭 https://t.co/azJu3SM3bd…
🤖 HackedGPT: Unpacking 7 Vulnerabilities we discovered in ChatGPT
Following up on our work: Yarden Curiel, Moshe Bernstein, and I are proud to share the technical details of our ChatGPT research
https://t.co/qAcAJvcrnN
🕵️#𝟭 𝗜𝗦𝗥𝗔𝗘𝗟 & #𝟭𝟴 𝗪𝗢𝗥𝗟𝗗𝗪𝗜𝗗𝗘: 𝗚𝗼𝗼𝗴𝗹𝗲 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵𝗲𝗿𝘀 𝗟𝗲𝗮𝗱𝗲𝗿𝗯𝗼𝗮𝗿𝗱
Massive personal milestone! 🎉 I'm ranked #1 in Israel and #18 worldwide on the Google VRP! Thrilled to be a part of it.