Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Researcher Secures 8,337 for Google Cloud Vulnerability

Researcher Secures $148,337 for Google Cloud Vulnerability

Posted on June 23, 2026 By CWS

A cybersecurity researcher recently received $148,337 from Google for identifying significant vulnerabilities in the Google Cloud Application Integration service. These vulnerabilities escalated to remote code execution (RCE) within Google’s production environment.

Critical Vulnerability Details

Identified as CVE-2026-2031, the vulnerability is a serious access control issue in the Google Cloud Application Integration, achieving a maximum CVSS score of 10.0. Arvin Shivram, the researcher who discovered the flaw, detailed his findings in a blog post titled “StubZero: $148,337 RCE in Google Cloud Production” on BruteCat.

Shivram’s exploration began with an automated tool that detected anomalies in the API cloudcrmipfrontend-pa.googleapis.com, which returned suspicious debugging responses. This led to further investigation of an endpoint that disclosed internal message schemas, vital for understanding Google’s API structure.

Exploitation Process and Discovery

The research revealed an API surface that exposed internal workflow data through a specific endpoint. By leveraging this information and a leaked client ID, Shivram created draft workflows, exploring various internal tasks documented within Google’s system. The pivotal discovery involved the GenericStubbyTypedTaskV2 task, which allowed for arbitrary RPC calls using privileged service identities.

Through these actions, Shivram demonstrated how Stubby-level access could lead to RCE in Google’s production environment, a scenario that Google classifies under their Cloud Vulnerability Reward Program as granting significant internal access.

Google’s Response and Mitigation

Initially, Google mitigated the vulnerability by restricting endpoint access and enhancing security protocols. However, Shivram, collaborating with another researcher, identified that these mitigations were not fully implemented across all backend instances. By targeting vulnerable instances, they maintained the exploit path temporarily.

Additionally, a second vulnerability chain involving insecure direct object references (IDOR) was discovered, allowing access to sensitive workflow definitions across different tenants.

Significant Reward and Conclusion

For his findings, Google awarded Shivram a total of $148,337, reflecting the critical impact of his discoveries. This included $60,000 for the initial chain, $75,000 for the subsequent IDOR-related findings, and $13,337 for a single-service privilege escalation issue.

The research underscores the importance of continuous monitoring and security assessment within cloud environments. It also highlights the role of responsible disclosure and reward programs in enhancing cybersecurity defenses.

For more updates, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:ACL bypass, application integration, bug bounty, cloud security, CVE-2026-2031, Cybersecurity, Google Cloud, IDOR, RCE, researcher reward, RPC security, Stubby RPC, vulnerability disclosure, workflow exploitation

Post navigation

Previous Post: London Hydro Investigates Customer Data Breach
Next Post: Malicious npm Packages Exploit PostCSS Tools for Windows RAT

Related Posts

BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies Cyber Security News
Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code Cyber Security News
Denodo Scheduler Vulnerability Let Attackers Execute Remote Code Denodo Scheduler Vulnerability Let Attackers Execute Remote Code Cyber Security News
Notepad++ v8.9.3 Enhances Security and Stability Notepad++ v8.9.3 Enhances Security and Stability Cyber Security News
Insider Threats in 2025 Detection and Prevention Strategies Insider Threats in 2025 Detection and Prevention Strategies Cyber Security News
New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark