CyberNotableConfirmedDeveloping
6.6
Security risks of IP-to-hostname obfuscation in SSRF mitigation
SANS Internet Storm CenterLO·2 days ago
Researchers identified a vulnerability where prompt injection in a public GitHub issue allowed unauthorized access to a Google Cloud project. The attack chain exploited an inactive tool allowlist and insecure credential storage in a CI runner, enabling service-account impersonation with Editor-level permissions. This highlights critical risks in automated CI/CD pipelines and the handling of cloud credentials in public-facing development environments.
Locations
Entities