• Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
No Result
View All Result
Home AI

Tenable Research Reveals Critical Security Flaws in Google Looker

SmartSolutionUser1 by SmartSolutionUser1
February 9, 2026
in AI
0
Tenable Research Reveals Critical Security Flaws in Google Looker
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Tenable Research has identified two major vulnerabilities dubbed “LookOut,” in Google Looker. The popular business intelligence platform is used by more than 60,000 companies in 195 countries, potentially allowing attackers to hijack entire systems or steal corporate secrets.

You might also like

2026 Smart City Summit & Expo – AI Creates New Urban Horizons

New Relic Introduces Platform Innovations to Connect Technical Performance with Business Outcomes

Honeywell Process Technology to Support Verso Energy in Advancing eSAF Production

The most critical discovery, a Remote Code Execution (RCE) chain, allows an attacker to take full control of a Looker server by running their own malicious commands remotely. This action essentially provides attackers with the “keys to the kingdom”, allowing them to steal sensitive secrets, manipulate data, or pivot further into the internal network. In cloud instances, the vulnerability could potentially lead to cross-tenant access.

Mr. Liv Matan, Senior Research Engineer at Tenable
Mr. Liv Matan, Senior Research Engineer at Tenable

“This level of access is particularly dangerous because Looker acts as a central nervous system for corporate information, and a breach could allow an attacker to manipulate data or move deeper into a company’s private internal network,” said Mr. Liv Matan, Senior Research Engineer at Tenable, who led the discovery.

The second vulnerability the research uncovered allows for the complete theft of Looker’s internal management database. By tricking the system into connecting to its own “private brain,” researchers used a specialized data-extraction technique to download sensitive user credentials and configuration secrets.

While Google responded quickly to secure its managed cloud service, the risk remains high for organizations that host Looker on their own private servers or on-premises hardware. These organizations must manually apply security patches to close these backdoors, as they currently bear the full burden of protecting their infrastructure from potential administrative takeover.

“Given that Looker is often the central nervous system for an organization’s most sensitive data, the security of its underlying architecture is crucial; however, it remains difficult to secure such systems while providing users with powerful capabilities like running SQL or indirectly interacting with the managing instance’s file system,” said Matan.

To monitor for potential exploitation of these vulnerabilities, administrators should review their systems for specific indicators of compromise. First, they should inspect the file system for any unexpected or unauthorized files within the .git/hooks/ directory of Looker project folders, paying close attention to scripts named pre-push, post-commit, or applypatch-msg that may have been placed there by an attacker. Additionally, security teams should examine application logs for signs of internal connection abuse, specifically searching for unusual SQL errors or patterns consistent with error-based SQL injection targeting internal Looker database connections like looker__ilooker.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com  roy@roymediative.com, 9811346846/9625243429.

Tags: Critical Security Flaws in Google Lookersmart solutions worldTenable Research
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

2026 Smart City Summit & Expo – AI Creates New Urban Horizons

by SmartSolutionUser1
March 9, 2026
0
2026 Smart City Summit & Expo – AI Creates New Urban Horizons

Taiwan is putting cities in control of their own AI brains. The 13th Smart City Summit & Expo (SCSE) and Net Zero City Exhibition opens March 17 at...

Read moreDetails

New Relic Introduces Platform Innovations to Connect Technical Performance with Business Outcomes

by SmartSolutionUser1
March 9, 2026
0
New Relic Introduces Platform Innovations to Connect Technical Performance with Business Outcomes

New Relic, the Intelligent Observability company, announced a series of platform innovations that connect technical performance to customer impact and business outcomes. Led by Intelligent Workloads that automate...

Read moreDetails

Honeywell Process Technology to Support Verso Energy in Advancing eSAF Production

by SmartSolutionUser1
March 9, 2026
0
Honeywell Process Technology to Support Verso Energy in Advancing eSAF Production

Honeywell announced that Verso Energy, an integrated energy company focused on producing low-carbon molecules, will use Honeywell UOP’s eFiningTM methanol-to-jet processing technology to produce electro-sustainable aviation fuel (eSAF)...

Read moreDetails

Splunk Report – Agentic AI Takes Centre Stage in CISOs’ Path to Digital Resilience

by SmartSolutionUser1
March 9, 2026
0
Splunk Report – Agentic AI Takes Centre Stage in CISOs’ Path to Digital Resilience

Cisco announced the release of Splunk’s annual report, The CISO Report: From Risk to Resilience in the AI Era, surveying 650 global Chief Information Security Officers (CISOs). The...

Read moreDetails

Airtel Payments Bank Launches Instant NFC-Based Balance Update for its RuPay On-The-Go Cards

by SmartSolutionUser1
March 9, 2026
0
Airtel Payments Bank Launches Instant NFC-Based Balance Update for its RuPay On-The-Go Cards

Airtel Payments Bank announced the launch of its Instant NFC-Based Balance Update feature for its RuPay On-The-Go Cards, enabled with NCMC. Customers can now instantly check or update...

Read moreDetails
Next Post
Aurionpro Wins Strategic Data Center Deal with IDBI Bank

Aurionpro Wins Strategic Data Center Deal with IDBI Bank

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Cloud Spending Grew 19% In Q2 2024

Migration To Oracle Cloud Improves Berger Paints’ Operational Efficiency By 25%

February 7, 2025
CyberArk Acquires Zilla Security For $175 Million

CyberArk Acquires Zilla Security For $175 Million

February 14, 2025
Check Point CloudGuard Recognised A Leader In Three GigaOm Radar Reports

Check Point CloudGuard Recognised A Leader In Three GigaOm Radar Reports

February 19, 2025

Browse by Category

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized
Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

CATEGORIES

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized

BROWSE BY TAG

Acquisition Agentic AI Agora AI Akamai AMD automation Cloudflare CloudKeeper CrowdStrike CyberArk Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud Honeywell IBM India AI Impact Summit 2026 Infosys Kaspersky Kramer LTIMindtree Microsoft New Relic NTT DATA Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm ServiceNow smart solutions world smartsolutionsworld smart solutions world latest news Snowflake Software Sophos Tata Communications Tech Mahindra Technology Tenable Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions

© 2024 NCN - Premium news & magazine by NCN.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?