A critical vulnerability in Google Cloud Platform, named “ConfusedComposer,” allowed attackers to escalate privileges to sensitive resources via Google Cloud Composer, a workflow orchestration service. By maliciously injecting PyPI packages, attackers could gain control of a highly privileged service account. Google has patched the issue, restructuring package handling to enhance security across GCP environments.

Cryptojacking Malware Exploits Docker for Token Mining
A new cryptojacking campaign is targeting Docker environments, exploiting the reward system of Web3 startup teneo.pro instead of typical tools like XMRig. The attackers generate