Connect with us

CyberSecurity

LeakyLooker: How Google Looker Vulnerabilities Risked Cloud Data

Published

on

The LeakyLooker Vulnerabilities in Google’s Analytics Platform

Imagine a business intelligence tool designed to visualize data becoming a backdoor to the cloud itself. That was the startling reality uncovered by Tenable Research, which identified a cluster of nine security flaws in Google Looker Studio. Dubbed ‘LeakyLooker,’ these cross-tenant vulnerabilities resided in the platform formerly known as Google Data Studio.

Looker Studio is a popular service for creating dashboards and reports. It pulls data from sources like Google BigQuery, Sheets, and other SQL databases. This deep integration with Google’s cloud infrastructure, however, painted an unexpectedly large target for attackers. The platform’s architecture inadvertently created a broad attack surface where a single compromised report could have far-reaching consequences.

Two Paths to Exploitation: Zero-Click and One-Click Attacks

Tenable’s investigation pinpointed weaknesses in the platform’s authentication and data connector systems. The core issue? Looker Studio can run queries using either the report creator’s credentials or the viewer’s credentials. This design flaw opened up two distinct avenues for malicious activity.

The first path required no user interaction. In a ‘0-click’ attack, a threat actor could craft server-side requests that triggered SQL queries executed with the report owner’s high-level permissions. No button click needed; the damage could be done remotely.

The second method was a ‘1-click’ attack. Here, a victim only needed to open a manipulated report or a malicious link. Upon viewing it, malicious SQL queries would run using the viewer’s own database credentials, potentially compromising their data.

Underlying Flaws That Enabled the Attacks

These attack techniques were powered by several critical underlying issues. Researchers found SQL injection flaws in the platform’s database connectors. Sensitive data could also leak through seemingly benign report elements like hyperlinks or embedded images. A particularly concerning flaw, dubbed a ‘denial-of-wallet’ issue, could have allowed attackers to run up massive bills on a victim’s BigQuery resources.

Potential Impact and the Path to Remediation

The scope was significant. Connectors for BigQuery, Cloud Spanner, PostgreSQL, MySQL, Google Sheets, and Cloud Storage were all affected. An attacker could have scoured the web for publicly shared Looker reports. These reports could then serve as a launchpad to steal data, insert false records, or even delete entire tables in connected databases.

One subtle but dangerous feature was the report copy function. When a viewer duplicated a report, it sometimes preserved the original database credentials. The new owner of the copied report could then run custom SQL queries against the original database, all without ever knowing the password.

Tenable responsibly disclosed all nine vulnerabilities to Google. The tech giant collaborated with the researchers to investigate and roll out fixes. Since Looker Studio is a fully managed service, Google deployed the patches globally. Customers did not need to take any action to be protected.

Securing Your Business Intelligence Front

This episode serves as a crucial reminder. Analytics and business intelligence platforms are often overlooked in security assessments. They are powerful tools that connect directly to crown-jewel data stores, making them attractive targets.

Organizations should proactively manage this risk. Regularly audit report-sharing settings and ensure only necessary individuals have access. Limit or remove unused data connectors to shrink the attack surface. Most importantly, treat BI and analytics integrations as a core component of your cloud security strategy, not an afterthought. The line between data visualization and data vulnerability can be thinner than it appears.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

Abstract Raises $25 Million to Expand Composable Security Operations Platform

Published

on

composable security operations

A New Bet Against the Old SIEM

For more than two decades, the SIEM has been the backbone of security operations. But a growing number of startups are betting that architecture is due for a reset. The latest to make that case is Abstract, which just closed a $25 million funding round to push its composable security operations platform further into the mainstream.

The round, announced Thursday, brings Abstract’s total raised to nearly $50 million. The company says its valuation has tripled since the last round — though it won’t say by how much.

Cheyenne Ventures and AVP co-led the investment, with participation from Olive Hill Ventures, Crosslink Capital, and Rally Ventures.

What ‘Composable’ Actually Means Here

The term gets thrown around a lot in cybersecurity. But Abstract has a specific definition. The company’s platform separates where security data comes from from where it ends up. That might sound simple, but it’s a break from the traditional SIEM model, where data ingestion, storage, detection, and analysis are tightly coupled inside a single vendor’s system.

Instead, Abstract lets organizations pick and choose components for collection, detection, retention, and AI-driven operations. Want to use one tool for detection and another for storage? That’s the idea. The platform is designed to mix and match without forcing a rip-and-replace of the entire stack.

It’s a modular approach — and one that a growing number of security teams are asking for as they grow tired of being locked into expensive, rigid SIEM contracts.

Streaming Detection: Catching Threats Before They Land

A key piece of the pitch is what Abstract calls streaming-first detection. Instead of waiting for data to be indexed and written to disk, the platform analyzes it while it’s still in motion. That means threats can be spotted in real time, not minutes or hours later when the logs finally finish processing.

Once data exits the pipeline, Abstract tiers and routes it to different storage destinations based on how it will be used. The platform converts data into standard schemas like OCSF, ECS, and CIM — formats that downstream tools can actually read. The goal: cut storage costs by keeping only what matters in expensive hot storage, while still retaining full visibility.

That kind of data routing flexibility is a direct challenge to legacy SIEM vendors, who often charge by the gigabyte for ingestion and storage alike.

AI Isn’t a Bolt-On — It’s the Architecture

Abstract’s CEO and co-founder Colby DeRodeff is blunt about where the industry is headed. “For more than two decades, SIEM has been the foundation of security operations. AI-Gen Security Operations is what’s next,” DeRodeff said in a statement.

He argues that AI can’t just be layered on top of an old system. “It’s woven into every layer of security operations,” he said. The platform embeds AI into detection, triage, investigation, and response — not as a chatbot sidebar, but as a core part of how the system processes and prioritizes data.

That’s a different bet than vendors who are retrofitting AI onto aging SIEM architectures. Abstract was built from scratch in 2023 with that vision in mind.

A Founding Team With Deep Roots

The company was founded by a team with backgrounds at ArcSight, Bank of America, Palo Alto Networks, and Mandiant. That pedigree matters. These are people who have spent years inside the SIEM ecosystem — and who know exactly where it falls short.

DeRodeff himself is a veteran of the security operations space, and his co-founders bring deep experience in both building detection engines and running SOCs at scale.

The new capital will go toward expanding Abstract’s in-stream detection coverage, building out more of the security operations workflow, and hiring for the go-to-market team. That last part is key: the company has a strong product story, but it needs to sell it to enterprises that are deeply invested in existing SIEM infrastructure.

The Funding Context

Abstract’s $25 million round lands in a market that is hungry for SIEM alternatives. Legacy vendors like Splunk and IBM have dominated for years, but their pricing models and architectural limitations have opened the door for challengers. Startups like Panther, Devo, and now Abstract are all vying for a piece of the pie.

The composable security operations approach is still relatively new, but it’s gaining traction. Organizations are tired of being locked into monolithic platforms that charge by the terabyte and take months to reconfigure. Abstract’s bet is that modularity — and the cost savings that come with it — will win the day.

Whether that bet pays off depends on execution. But with nearly $50 million in the bank and a valuation that’s tripled, the market is signaling that it likes what it sees.

Continue Reading

CyberSecurity

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Published

on

free Android VPN leak

Your Free VPN Might Be a Sham — Here’s the Proof

You download a free VPN from the Google Play Store. You think your traffic is hidden, your data is safe. But a sweeping new study suggests otherwise. Researchers put 281 of the most popular free Android VPN apps through a rigorous testing system. The results are ugly.

Many of these apps fail at the one basic job people install them for: keeping traffic private and secure. The apps flagged with at least one serious problem have been installed more than 2.4 billion times. That’s billions of users whose privacy may be compromised.

And these aren’t sophisticated attacks. These are basic failures. 29 apps let user traffic leak outside the VPN tunnel entirely. That means your real IP address and browsing activity are exposed, even while the VPN claims to be protecting you.

Another batch of apps sends user data — including login credentials and browsing history — completely unencrypted. Some even hardcode API keys and secret tokens into the app code, making it trivial for anyone to intercept or hijack the service.

The study, conducted by researchers using a new automated testing framework, looked at the top free VPNs by download count on Google Play. They didn’t name every single offender, but the pattern is clear: free VPNs are often a privacy nightmare.

What Exactly Did the Researchers Find?

The team built a system called VPNalyzer to automatically test each app. They checked for six core problems:

  • Traffic leaks — data escaping the VPN tunnel (29 apps)
  • Unencrypted traffic — sensitive data sent in plaintext
  • Hardcoded secrets — API keys, tokens, or credentials baked into the app
  • DNS leaks — domain requests visible to your ISP
  • IPv6 leaks — traffic bypassing the VPN over IPv6
  • Aggressive tracking — third-party SDKs collecting data for ad networks

More than half the apps had at least one of these issues. Some had multiple. The most common problem? Tracking. Many free VPNs are packed with analytics and ad SDKs from companies like Google, Facebook, and dozens of lesser-known trackers. You install a privacy tool, and it becomes a surveillance tool instead.

Why Free VPNs Are So Dangerous

Running a VPN costs money — servers, bandwidth, maintenance. If you’re not paying, you’re the product. That old adage holds brutally true here. Free VPNs have to make money somehow, and many do it by selling your data, showing you ads, or upselling you to a paid plan.

But the study shows it’s worse than just data collection. Some apps are so poorly coded that they actively undermine your security. Leaking traffic outside the tunnel is a catastrophic failure. It means your real IP is visible to every website you visit. Your ISP can see everything. The VPN is doing nothing.

Unencrypted data is another shocker. Modern web traffic is mostly encrypted anyway (HTTPS), but not everything. DNS queries, for example, are often sent in plaintext. A good VPN encrypts everything. A bad one leaves you exposed.

Hardcoded secrets are a developer sin. If an app stores its API key in the code, anyone who decompiles the app can steal that key and use it to access the VPN provider’s backend. That could mean free service for attackers — or worse, a way to intercept other users’ connections.

How to Pick a VPN That Actually Works

Not all VPNs are bad. But the free ones on Google Play are a minefield. If you need a VPN, here’s what to look for:

  • Paid services — A reputable paid VPN has a business model that doesn’t rely on selling your data. You pay for the service.
  • Independent audits — Look for VPNs that have been audited by third-party security firms. They publish the results.
  • No-log policy — The provider should promise not to log your activity. Check if they’ve proven it in court.
  • Open-source apps — If the code is open, anyone can check for leaks or tracking. It’s not a guarantee, but it’s a good sign.
  • Kill switch — A proper VPN has a kill switch that blocks all internet traffic if the VPN connection drops. This prevents leaks.

Some of the safer options include ProtonVPN (which has a free tier with no data limits and no ads) and Mullvad (a paid service known for strong privacy). Both have been independently audited.

The Bottom Line: Free VPNs Are a Bad Bet

The study of 281 free Android VPN apps is a wake-up call. Over 2.4 billion installs — and a huge chunk of those users are getting a false sense of security. Their traffic leaks, their data is unencrypted, and they’re being tracked.

If you care about privacy, do not trust a free VPN. Not without serious vetting. Even then, be skeptical. The safest bet is a paid, audited service that doesn’t need to monetize your data.

For more on staying safe online, check out our guide on how to check if your VPN is leaking your IP and our comparison of the best VPNs for Android in 2025.

Continue Reading

CyberSecurity

Estée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day Attack

Published

on

Estée Lauder data breach

A Delayed Disclosure, a Massive Data Haul

Nearly a year after the infamous Cl0p cybercrime group exploited a critical vulnerability in Oracle E-Business Suite (EBS), cosmetics giant Estée Lauder has finally begun notifying employees that their personal information was stolen. The breach, which the company says occurred in early August 2025, leveraged a zero-day flaw — tracked as CVE-2025-61882 — that allowed unauthenticated remote code execution.

The Cl0p group wasted no time. By November 2025, over 100 companies found themselves listed on Cl0p’s leak site. Most confirmed the impact quickly. Estée Lauder did not. It took until March 2026 for the group to dump 870GB of archive files allegedly stolen from the company, making Estée Lauder one of the last major holdouts — alongside Broadcom, Bechtel, and Abbott Laboratories — to disclose the full scope of the damage.

What Was Stolen? A Full HR Dossier

The notification letter, filed with the California Attorney General’s Office, spells it out in grim detail. Estée Lauder’s Oracle EBS instance was used for HR management. That means the compromised data reads like a complete employee dossier: names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and payroll records.

It’s hard to overstate how sensitive that mix is. Bank details alone can fuel fraud. Combine them with SSNs and health data, and you have the raw material for identity theft that can plague victims for years. Estée Lauder is offering 24 months of free identity monitoring to those affected — a standard but necessary step.

The Timeline: How the Attack Unfolded

The zero-day itself was patched by Oracle in early October 2025. Shortly after, CrowdStrike confirmed that in-the-wild exploitation had begun on August 9 — the same day Estée Lauder was hit. The company’s internal investigation only concluded in June 2026, determining that data had indeed been exfiltrated from its EBS system.

That’s a long gap between intrusion and confirmation. Security teams often struggle to piece together what exactly was taken, especially when attackers have had months to cover their tracks. But a year-long investigation raises questions about visibility and logging within Estée Lauder’s Oracle environment.

Why the Delay?

Estée Lauder hasn’t explained why the notification took so long. The company says it has notified law enforcement and taken steps to harden its systems. It has not disclosed how many employees are affected. SecurityWeek has reached out for comment but has not yet received a response.

The Bigger Picture: Cl0p’s Oracle EBS Campaign

This wasn’t just a one-off breach. CVE-2025-61882 was a zero-day in Oracle EBS — a widely used enterprise resource planning platform. Cl0p, known for its big-game hunting tactics, scanned for vulnerable instances and punched through. The campaign hit dozens of organizations across industries, from manufacturing to healthcare.

What makes this incident particularly concerning is the nature of the data. Oracle EBS often centralizes HR, finance, and supply chain operations. When an attacker gains access to that system, they don’t just grab a few emails. They pull the company’s entire internal operating picture.

What Estée Lauder Employees Should Do Now

For the affected employees, the advice is straightforward but critical. Monitor bank accounts for unauthorized transactions. Watch for phishing emails that reference your stolen data — Cl0p or other criminals may try to weaponize the information. Place a fraud alert or credit freeze with the major credit bureaus. Estée Lauder’s identity monitoring service is a good start, but it’s not a silver bullet.

The company is also urging vigilance against suspicious calls and texts. Social engineering attacks often follow data breaches, with criminals posing as HR or IT support to extract even more information.

Lessons for Enterprise Security Teams

This breach underscores a few hard truths. First, zero-day vulnerabilities in legacy ERP systems are a ticking clock. Oracle EBS is decades old, but it’s still the backbone of HR and finance operations at thousands of companies. Patching alone isn’t enough — segmentation, monitoring, and incident response plans need to assume that an attacker will eventually get in.

Second, disclosure timelines matter. A year-long investigation erodes trust and leaves employees in the dark. Faster, more transparent communication — even if the full picture isn’t clear — can help mitigate the fallout.

Finally, the Cl0p group isn’t going anywhere. They’ve proven they can exploit enterprise software at scale and hold data for ransom or exposure. Companies running Oracle EBS should treat that as a given, not a possibility.

This is a developing story. SecurityWeek will update this article if Estée Lauder provides additional details on the number of impacted individuals or the remediation steps taken.

Continue Reading

Trending