Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Google Cloud to Assign CVEs to Critical Vulnerabilities 

Google Cloud will be assigning CVE identifiers to serious cloud vulnerabilities, even ones that don’t require patching.

Google Cloud CVE

Google Cloud announced on Tuesday that moving forward it will assign CVE identifiers to critical vulnerabilities found in its products, even if they do not require the user to deploy patches or take other action.

Critical Google Cloud flaws that will receive CVEs will have advisories published on the Google Cloud Security Bulletins page. 

A tag named ‘exclusively-hosted-service’ will indicate that customers do not need to take any action for a specific vulnerability. 

The expansion of its CVE program is part of its commitment to transparency, Google Cloud said. 

The cloud giant recently announced a new Vulnerability Reward Program (VRP) with bug bounties of up to $100,000 for security issues found in its products and services. 

“While the Google Cloud VRP has a specific focus on strengthening Google Cloud products and services, and brings together our engineers with external security researchers to further the security posture for all our customers, CVEs enable us to help our customers and security researchers track publicly-known vulnerabilities,” Google Cloud representatives said in a blog post.

Advertisement. Scroll to continue reading.

Google Cloud joins Microsoft, which has been assigning CVE identifiers and publishing advisories for cloud vulnerabilities that do not require any user interaction since June 2024. 

Amazon Web Services (AWS) has also been issuing CVE identifiers for vulnerabilities affecting its cloud products and services. 

Cloud security giant Wiz has been maintaining a database of cloud vulnerabilities since 2022. The database currently stores information on nearly 200 security issues found between 2008 and present day.

The CVE Program recently turned 25. There are currently over 400 CVE Numbering Authorities (CNAs) and more than 240,000 CVE identifiers were assigned as of October 2024. 

Related: CISA Announces CVE Enrichment Project ‘Vulnrichment’

Related: CVE and NVD – A Weak and Fractured Source of Vulnerability Truth

Related: Dependency Confusion Could Have Led to RCE in Google Cloud Platform

Related: Google Cloud Rolling Out Mandatory MFA for All Users

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.