The Containment Era is here. →Explore

Executive Summary

In March 2026, Tenable Research disclosed nine critical cross-tenant vulnerabilities, collectively termed 'LeakyLooker,' in Google Looker Studio. These flaws allowed attackers to execute arbitrary SQL queries on victims' databases, leading to potential data exfiltration, insertion, and deletion across Google Cloud Platform (GCP) services. The vulnerabilities affected organizations utilizing connectors such as Google Sheets, BigQuery, Spanner, PostgreSQL, MySQL, and Cloud Storage. Google addressed these issues following responsible disclosure in June 2025. The 'LeakyLooker' vulnerabilities underscore the evolving threat landscape in cloud environments, highlighting the necessity for robust security measures and continuous monitoring. Organizations must remain vigilant against cross-tenant vulnerabilities to safeguard sensitive data and maintain compliance with industry standards.

Why This Matters Now

The 'LeakyLooker' vulnerabilities highlight the critical need for organizations to reassess and strengthen their cloud security postures. As cloud services become increasingly integrated into business operations, the potential for cross-tenant attacks grows, making it imperative to implement stringent access controls and continuous monitoring to protect sensitive data.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Frequently Asked Questions

The 'LeakyLooker' vulnerabilities are nine critical cross-tenant security flaws in Google Looker Studio that allowed attackers to execute arbitrary SQL queries on victims' databases, potentially leading to data exfiltration, insertion, and deletion across Google Cloud Platform services.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit cross-tenant vulnerabilities, thereby reducing the potential for unauthorized access and data exfiltration across cloud tenants.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit cross-tenant vulnerabilities would likely be constrained, reducing unauthorized access to databases.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges and execute arbitrary SQL queries would likely be constrained, reducing unauthorized database operations.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement across cloud tenants would likely be constrained, reducing unauthorized access to multiple datasets and projects.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish control over databases and issue commands would likely be constrained, reducing data manipulation and exfiltration.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data to external destinations would likely be constrained, reducing data loss.

Impact (Mitigations)

The attacker's ability to modify or delete data would likely be constrained, reducing data integrity issues and operational disruptions.

Impact at a Glance

Affected Business Functions

  • Data Analytics
  • Business Intelligence
  • Data Visualization
  • Reporting
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive organizational data stored in Google Cloud Platform services such as BigQuery, Spanner, and Google Sheets.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
  • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows, mitigating lateral movement risks.
  • Utilize Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
  • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
  • Regularly update and patch systems to address known vulnerabilities and reduce the attack surface.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image