Close Menu
NCIJ Network NCIJ Network
    What's Hot

    RAM costs more for phones, too – so how much do you actually need?

    July 27, 2026

    What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

    July 27, 2026

    Bitcoin (BTC) price may fall to $52,000 as demand remains elusive, Nansen analyst says

    July 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • RAM costs more for phones, too – so how much do you actually need?
    • What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
    • Bitcoin (BTC) price may fall to $52,000 as demand remains elusive, Nansen analyst says
    • Lough Neagh eels: Prehistoric species fights for survival
    • Israel’s Netanyahu Heads to the White House for Talks With Trump
    • Did Alysa Liu share Mamdani’s call for Netanyahu’s arrest?
    • A Japanese town wrestles with identity after protests over its first mosque
    • Police make inquiries after Farage reports Polanski post for ‘inciting murder’ | Nigel Farage
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, July 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 27, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Significant cracks in the managed identity trust chains of the world’s biggest cloud platforms could put enterprise and government resources at risk.

    That’s according to Justin O’Leary, independent security researcher, who discovered two “confused deputy” vulnerabilities in both Microsoft Azure and the Google Cloud Platform (GCP) earlier this year. Despite reporting them to the cloud giants, neither company acknowledged the vulnerabilities or paid a bug-bounty reward, even though Microsoft appears to have silently patched its flaw.

    Confused deputy issues arise when a product or service receives a request from an upstream entity but fails to preserve the original source of request and even allows it to be forwarded to external parties. A threat actor can trick a high-privileged entity into accepting the request, which appears as if it’s coming from the original product or service and allows the attacker to bypass access controls such as firewalls.

    Related:Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

    Computer scientist Norm Hardy first coined the term in a 1988 paper after discovering a vulnerability more than a decade earlier in the compiler program at Tymshare, a commercial time-sharing firm in Silicon Valley. Despite the enormous advancements in IT, most notably in identity and access management (IAM), confused deputy flaws still persist today, nearly 40 years after Hardy’s paper.

    This, O’Leary tells Dark Reading, is because many companies have gotten into some bad habits. “My feeling is that this problem is still around, because when you’re building these big cloud infrastructures, you’re often doing it in a cookie-cutter approach,” he says.

    Big Confused Deputy Flaws in Azure, GCP

    O’Leary says the vulnerabilities illustrate a pattern of fundamental weaknesses rather than just a series of isolated bugs. In an on-demand session at Black Hat USA 2026 next week, “Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains,” he will detail how the issue, tracked as CWE-114 under Mitre’s Common Weakness Enumeration, has become a pervasive problem for modern cloud architectures.

    The first flaw, which O’Leary disclosed on May 12, involves Microsoft’s Azure Kubernetes Service (AKS) backup service. The service uses a feature called Trusted Access to give the backup vault access to the AKS cluster through specific, assigned permissions.

    However, O’Leary found that an attacker can exploit a confused deputy flaw to escalate privileges from a basic Backup Contributor level, which has no Kubernetes permissions at all, to achieve cluster-admin privileges for the AKS. With such access, the attacker can exfiltrate sensitive data from backups or deploy malicious workloads to any cluster in the network.

    Related:Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers

    O’Leary disclosed a second confused deputy flaw on June 18, this time an IAM bypass in GCP. The issue involves Config Connector, an open source add-on that lets users manage their Google cloud resources via Kubernetes. According to O’Leary’s research, Config Connector doesn’t perform authorization checks to confirm the user’s identity against Google’s IAM, bypassing the platform’s access controls.

    “When a Kubernetes user submits an IAMPolicyMember referencing an external organization, Config Connector should verify: does this user have permission to grant IAM roles on this organization?” he wrote in a blog post. “It doesn’t. It passes the user-supplied organization ID directly to the GCP API using its own elevated credentials.”

    As a result, a threat actor equipped with basic Kubernetes namespace access and no GCP permissions can use Config Connector to quickly establish themself as GCP Organization Owner with full administrative control. Additionally, the threat actor’s actions are logged as service account activity, which disguises the attack.

    “The worst part, the part that people should be worried about, is you actually don’t see the attacker in the cloud audit logs,” he says. “The attacker is essentially invisible.”

    Related:Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

    Disclosure Discord for Confused Deputy Flaws

    After discovering the bugs and reporting them to Microsoft and Google, O’Leary ultimately found himself in frustrating situations where both companies ultimately declined to recognize the issues as vulnerabilities that required fixing, he tells Dark Reading.

    In the case of the Azure flaw, O’Leary discovered that after communicating with Microsoft and CERT/CC, the software giant had apparently closed the attack vector with a silent patch.

    “A silent patch is an admission,” O’Leary explains, adding that such practices only protect vendors while making it hard for customers to track exposures and threats.

    In Google’s case, the researcher initially got a positive response from the company and was in line for a bug-bounty reward. But the good vibes didn’t last long, as a Google Vulnerability Rewards Program (VRP) panel ultimately decided it wasn’t a vulnerability.

    “They said they might fix it, but that it didn’t qualify for a bounty,” O’Leary says. “The contradictions were wild.”

    Google appeared to argue that customers are responsible for setting the appropriate permissions of Config Connector, but O’Leary says this misses the point — the connector doesn’t verify if the user is authorized to request those permissions on a specific target, and Google has no means of preventing the abuse.

    O’Leary notes that Config Connector is deployed across many large enterprises and government agencies, including FedRAMP-authorized GCP environments, and that Google’s documentation for the tool doesn’t properly communicate the risks of a confused deputy attack.

    Google and Microsoft are hardly alone when it comes to confused deputy issues, O’Leary says, adding that these kinds of connectors used by other major cloud providers. He adds that credential scoping and trust boundary separations can help reduce confused deputy risks within customers’ cloud environments.

    “I think it’s a systemic problem,” he says.

    Azure cloud Confused Deputy flaws Google Microsoft persist
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

    The containment paradox: Why your ransomware playbook has the wrong people in charge

    PSA: Your Claude shared chats and Artifacts may have ended up on Google

    Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

    Beelzebub Raises $3.4 Million for Hacker-Trapping Platform

    Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    RAM costs more for phones, too – so how much do you actually need?

    July 27, 2026

    What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

    July 27, 2026

    Bitcoin (BTC) price may fall to $52,000 as demand remains elusive, Nansen analyst says

    July 27, 2026

    Lough Neagh eels: Prehistoric species fights for survival

    July 27, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    RAM costs more for phones, too – so how much do you actually need?

    July 27, 2026

    What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

    July 27, 2026

    Bitcoin (BTC) price may fall to $52,000 as demand remains elusive, Nansen analyst says

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.