Critical Flaw: How Attackers Exploited GCP Cloud Composer to Gain Elevated Privileges Through Malicious PyPI Packages
A critical vulnerability named "ConfusedComposer" in Google Cloud Platform's Cloud Composer service allows attackers with edit permissions to escalate privileges across multiple GCP services. Discovered by Tenable researchers, the flaw enables exploitation of the default Cloud Build servic...
