Close Menu
  • Home
  • Education
  • Health
  • National News
  • Politics
  • Relationship & Wellness
  • World News
What's Hot

Burnt-out vehicles, rock-strewn roads, heavy security: PoK votes in second phase amid unrest

August 2, 2026

'Dismantle terror infrastructure first': India's US envoy hits out at Pakistan over Indus Waters Treaty

August 2, 2026

When Apple CEO Tim Cook told the iPhone users that Facebook tracks 'you' across companies' apps and websites

August 2, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Global News Bulletin
SUBSCRIBE
  • Home
  • Education
  • Health
  • National News
  • Politics
  • Relationship & Wellness
  • World News
Global News Bulletin
Home»National News»Security flaws in Google’s Looker expose firms to data theft, system takeover: Report
National News

Security flaws in Google’s Looker expose firms to data theft, system takeover: Report

editorialBy editorialFebruary 9, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
Security flaws in Google’s Looker expose firms to data theft, system takeover: Report
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

3 min readNew DelhiUpdated: Feb 9, 2026 08:27 AM IST

Security researchers said they have found two major vulnerabilities in Google’s business intelligence platform, Looker, that could potentially enable hackers to take over “entire systems” and “steal corporate secrets”.

Collectively dubbed as ‘LookOut’, one of the platform’s vulnerabilities involves a Remote Code Execution (RCE) chain that could allow an attacker to take full control of a Looker server by running their own malicious commands remotely, researchers at cybersecurity firm Tenable said in a blog post on Thursday, February 5.

The Google-owned business intelligence platform is reportedly used by more than 60,000 companies in 195 countries. Hackers targeting cloud instances of Looker could potentially exploit security flaws to gain cross-tenant access, as per the researchers. They further said that companies were vulnerable to the complete theft of Looker’s internal management database.

“By tricking the system into connecting to its own ‘private brain’ researchers used a specialised data-extraction technique to download sensitive user credentials and configuration secrets,” Tenable said.

“This level of access is particularly dangerous because Looker acts as a central nervous system for corporate information, and a breach could allow an attacker to manipulate data or move deeper into a company’s private internal network,” Liv Matan, Senior Research Engineer at Tenable, said.

The researchers acknowledged that Google responded quickly to secure its managed cloud version of Looker after the vulnerabilities were reported to the tech giant. However, they also said that organisations hosting Looker on their own private servers or on-prem hardware might still be vulnerable.

“These organisations must manually apply security patches to close these backdoors, as they currently bear the full burden of protecting their infrastructure from potential administrative takeover,” Tenable said.

Story continues below this ad

What is Looker?

Looker, based in Santa Cruz, California, helps companies visualise and analyse the data they store in the cloud. Google agreed to buy Looker for $2.6 billion in 2019, expanding its offerings to help customers manage data in the cloud, according to a report by Bloomberg.

The Looker acquisition is said to have given Google another tool in its larger campaign to sell more cloud storage and software.

How can users protect themselves?

In order to avoid the potential exploitation of these vulnerabilities, Tenable researchers recommended that administrators should review their systems for specific indicators of compromise.

“First, they should inspect the file system for any unexpected or unauthorised files within the .git/hooks/ directory of Looker project folders, paying close attention to scripts named pre-push, post-commit, or applypatch-msg that may have been placed there by an attacker,” the company said.

Story continues below this ad

“Additionally, security teams should examine application logs for signs of internal connection abuse, specifically searching for unusual SQL errors or patterns consistent with error-based SQL injection targeting internal Looker database connections like looker__ilooker,” it added.

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTrade deal will give new wings to farmers' dreams: Shivraj Singh Chouhan | India News – The Times of India
Next Article Electronics output up 6-fold, exports 8-fold in 11 yrs: Govt | India News – The Times of India
editorial
  • Website

Related Posts

Left teaching for farming, Haryana professor earns crores from polyhouse business

July 31, 2026

Entire Gurugram-Jaipur corridor on NH-48 likely to go barrier-less from August 1

July 31, 2026

Inside Vedika Pinto’s sea-facing Mumbai home with a Goan charm, and a ‘covered up’ painting

July 31, 2026

Indian Railways approves Rs 299 crore Visakhapatnam Coaching Yard upgrade to handle more trains

July 31, 2026

Cauvery water protesters stop screening of Vijay’s ‘Jana Nayagan’ in Mysuru

July 31, 2026

Prosperity or distress: What drove the rise of rural non-farm employment

July 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

Burnt-out vehicles, rock-strewn roads, heavy security: PoK votes in second phase amid unrest

By editorialAugust 2, 2026

The elections in Pakistan-occupied Jammu & Kashmir (PoK) have been overshadowed by violence, allegations of…

'Dismantle terror infrastructure first': India's US envoy hits out at Pakistan over Indus Waters Treaty

August 2, 2026

When Apple CEO Tim Cook told the iPhone users that Facebook tracks 'you' across companies' apps and websites

August 2, 2026
Top Trending

Burnt-out vehicles, rock-strewn roads, heavy security: PoK votes in second phase amid unrest

By editorialAugust 2, 2026

The elections in Pakistan-occupied Jammu & Kashmir (PoK) have been overshadowed by…

'Dismantle terror infrastructure first': India's US envoy hits out at Pakistan over Indus Waters Treaty

By editorialAugust 2, 2026

India’s envoy to the US, Vinay Mohan Kwatra said Pakistan had eroded…

When Apple CEO Tim Cook told the iPhone users that Facebook tracks 'you' across companies' apps and websites

By editorialAugust 2, 2026

Apple has developed much of its brand image around privacy, making it…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

Facebook X (Twitter) Instagram YouTube

News

  • Education
  • Health
  • National News
  • Relationship & Wellness
  • World News
  • Politics

Company

  • Information
  • Advertising
  • Classified Ads
  • Contact Info
  • Do Not Sell Data
  • GDPR Policy
  • Media Kits

Services

  • Subscriptions
  • Customer Support
  • Bulk Packages
  • Newsletters
  • Sponsored News
  • Work With Us

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

© Copyright Global News Bulletin.
  • Privacy Policy
  • Terms
  • Accessibility
  • Website Developed by Plenary Media Solution

Type above and press Enter to search. Press Esc to cancel.