Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Researcher Secures 8,337 for Google Cloud Vulnerability

Researcher Secures $148,337 for Google Cloud Vulnerability

Posted on June 23, 2026 By CWS

A cybersecurity researcher recently received $148,337 from Google for identifying significant vulnerabilities in the Google Cloud Application Integration service. These vulnerabilities escalated to remote code execution (RCE) within Google’s production environment.

Critical Vulnerability Details

Identified as CVE-2026-2031, the vulnerability is a serious access control issue in the Google Cloud Application Integration, achieving a maximum CVSS score of 10.0. Arvin Shivram, the researcher who discovered the flaw, detailed his findings in a blog post titled “StubZero: $148,337 RCE in Google Cloud Production” on BruteCat.

Shivram’s exploration began with an automated tool that detected anomalies in the API cloudcrmipfrontend-pa.googleapis.com, which returned suspicious debugging responses. This led to further investigation of an endpoint that disclosed internal message schemas, vital for understanding Google’s API structure.

Exploitation Process and Discovery

The research revealed an API surface that exposed internal workflow data through a specific endpoint. By leveraging this information and a leaked client ID, Shivram created draft workflows, exploring various internal tasks documented within Google’s system. The pivotal discovery involved the GenericStubbyTypedTaskV2 task, which allowed for arbitrary RPC calls using privileged service identities.

Through these actions, Shivram demonstrated how Stubby-level access could lead to RCE in Google’s production environment, a scenario that Google classifies under their Cloud Vulnerability Reward Program as granting significant internal access.

Google’s Response and Mitigation

Initially, Google mitigated the vulnerability by restricting endpoint access and enhancing security protocols. However, Shivram, collaborating with another researcher, identified that these mitigations were not fully implemented across all backend instances. By targeting vulnerable instances, they maintained the exploit path temporarily.

Additionally, a second vulnerability chain involving insecure direct object references (IDOR) was discovered, allowing access to sensitive workflow definitions across different tenants.

Significant Reward and Conclusion

For his findings, Google awarded Shivram a total of $148,337, reflecting the critical impact of his discoveries. This included $60,000 for the initial chain, $75,000 for the subsequent IDOR-related findings, and $13,337 for a single-service privilege escalation issue.

The research underscores the importance of continuous monitoring and security assessment within cloud environments. It also highlights the role of responsible disclosure and reward programs in enhancing cybersecurity defenses.

For more updates, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:ACL bypass, application integration, bug bounty, cloud security, CVE-2026-2031, Cybersecurity, Google Cloud, IDOR, RCE, researcher reward, RPC security, Stubby RPC, vulnerability disclosure, workflow exploitation

Post navigation

Previous Post: London Hydro Investigates Customer Data Breach
Next Post: Malicious npm Packages Exploit PostCSS Tools for Windows RAT

Related Posts

CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks Cyber Security News
Magecart Hackers Exploit 100 Domains to Steal Card Data Magecart Hackers Exploit 100 Domains to Steal Card Data Cyber Security News
British Hacker Admits to Stealing Millions in Cryptocurrency British Hacker Admits to Stealing Millions in Cryptocurrency Cyber Security News
Microsoft Defender Misidentifies DigiCert Certificates Microsoft Defender Misidentifies DigiCert Certificates Cyber Security News
Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable Cyber Security News
Android Malware Masquerades as RTO Notifications Android Malware Masquerades as RTO Notifications Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dropping Elephant’s Deceptive New Cyber Tactics Unveiled
  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark