Close Menu
  • Home
  • Education
  • Health
  • National News
  • Politics
  • Relationship & Wellness
  • World News
What's Hot

BJP drops 'Greater Kashmir' charge, backs J&K reorganisation bill | India News – The Times of India

March 30, 2026

860 trains, 3 months: Punjab to transport out freshly procured wheat from mandis

March 30, 2026

Transport ministry proposes secured cover for moving dumpers, tippers | India News – The Times of India

March 30, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Global News Bulletin
SUBSCRIBE
  • Home
  • Education
  • Health
  • National News
  • Politics
  • Relationship & Wellness
  • World News
Global News Bulletin
Home»National News»Security flaws in Google’s Looker expose firms to data theft, system takeover: Report
National News

Security flaws in Google’s Looker expose firms to data theft, system takeover: Report

editorialBy editorialFebruary 9, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
Security flaws in Google’s Looker expose firms to data theft, system takeover: Report
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

3 min readNew DelhiUpdated: Feb 9, 2026 08:27 AM IST

Security researchers said they have found two major vulnerabilities in Google’s business intelligence platform, Looker, that could potentially enable hackers to take over “entire systems” and “steal corporate secrets”.

Collectively dubbed as ‘LookOut’, one of the platform’s vulnerabilities involves a Remote Code Execution (RCE) chain that could allow an attacker to take full control of a Looker server by running their own malicious commands remotely, researchers at cybersecurity firm Tenable said in a blog post on Thursday, February 5.

The Google-owned business intelligence platform is reportedly used by more than 60,000 companies in 195 countries. Hackers targeting cloud instances of Looker could potentially exploit security flaws to gain cross-tenant access, as per the researchers. They further said that companies were vulnerable to the complete theft of Looker’s internal management database.

“By tricking the system into connecting to its own ‘private brain’ researchers used a specialised data-extraction technique to download sensitive user credentials and configuration secrets,” Tenable said.

“This level of access is particularly dangerous because Looker acts as a central nervous system for corporate information, and a breach could allow an attacker to manipulate data or move deeper into a company’s private internal network,” Liv Matan, Senior Research Engineer at Tenable, said.

The researchers acknowledged that Google responded quickly to secure its managed cloud version of Looker after the vulnerabilities were reported to the tech giant. However, they also said that organisations hosting Looker on their own private servers or on-prem hardware might still be vulnerable.

“These organisations must manually apply security patches to close these backdoors, as they currently bear the full burden of protecting their infrastructure from potential administrative takeover,” Tenable said.

Story continues below this ad

What is Looker?

Looker, based in Santa Cruz, California, helps companies visualise and analyse the data they store in the cloud. Google agreed to buy Looker for $2.6 billion in 2019, expanding its offerings to help customers manage data in the cloud, according to a report by Bloomberg.

The Looker acquisition is said to have given Google another tool in its larger campaign to sell more cloud storage and software.

How can users protect themselves?

In order to avoid the potential exploitation of these vulnerabilities, Tenable researchers recommended that administrators should review their systems for specific indicators of compromise.

“First, they should inspect the file system for any unexpected or unauthorised files within the .git/hooks/ directory of Looker project folders, paying close attention to scripts named pre-push, post-commit, or applypatch-msg that may have been placed there by an attacker,” the company said.

Story continues below this ad

“Additionally, security teams should examine application logs for signs of internal connection abuse, specifically searching for unusual SQL errors or patterns consistent with error-based SQL injection targeting internal Looker database connections like looker__ilooker,” it added.

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTrade deal will give new wings to farmers' dreams: Shivraj Singh Chouhan | India News – The Times of India
Next Article Electronics output up 6-fold, exports 8-fold in 11 yrs: Govt | India News – The Times of India
editorial
  • Website

Related Posts

860 trains, 3 months: Punjab to transport out freshly procured wheat from mandis

March 30, 2026

Intisab: In the name of this day, and all our days

March 30, 2026

Everything from iPhones and PlayStations to your Netflix subscription is about to get a lot more expensive

March 30, 2026

Biharboardonline.bihar.gov.in, Bihar Board 10th Result 2026 [OUT] LIVE: BSEB Matric Results link active, check complete list of toppers

March 30, 2026

Bihar Board 10th Class Result 2026 declared at result.biharboardonline.org and matricbiharboard.com

March 29, 2026

From Rajnath & Mayawati to Akhilesh & Yogi: What is the politics behind Jewar airport?

March 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

BJP drops 'Greater Kashmir' charge, backs J&K reorganisation bill | India News – The Times of India

By editorialMarch 30, 2026

SRINAGAR: BJP dropped Sunday its earlier “Greater Kashmir” charge and backed a PDP-sponsored territorial reorganisation…

860 trains, 3 months: Punjab to transport out freshly procured wheat from mandis

March 30, 2026

Transport ministry proposes secured cover for moving dumpers, tippers | India News – The Times of India

March 30, 2026
Top Trending

BJP drops 'Greater Kashmir' charge, backs J&K reorganisation bill | India News – The Times of India

By editorialMarch 30, 2026

SRINAGAR: BJP dropped Sunday its earlier “Greater Kashmir” charge and backed a…

860 trains, 3 months: Punjab to transport out freshly procured wheat from mandis

By editorialMarch 30, 2026

Battling a severe storage crunch ahead of the upcoming wheat procurement season,…

Transport ministry proposes secured cover for moving dumpers, tippers | India News – The Times of India

By editorialMarch 30, 2026

NEW DELHI: Road transport ministry has proposed to mandate all dumpers and…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

Facebook X (Twitter) Instagram YouTube

News

  • Education
  • Health
  • National News
  • Relationship & Wellness
  • World News
  • Politics

Company

  • Information
  • Advertising
  • Classified Ads
  • Contact Info
  • Do Not Sell Data
  • GDPR Policy
  • Media Kits

Services

  • Subscriptions
  • Customer Support
  • Bulk Packages
  • Newsletters
  • Sponsored News
  • Work With Us

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

© Copyright Global News Bulletin.
  • Privacy Policy
  • Terms
  • Accessibility
  • Website Developed by Plenary Media Solution

Type above and press Enter to search. Press Esc to cancel.