KUALA LUMPUR, March 11 — Tenable Research has uncovered two major vulnerabilities, dubbed “LookOut,” in Google Looker, a widely used business intelligence platform serving over 60,000 organisations worldwide, which could allow attackers to take full control of servers or steal sensitive corporate data.
The most severe flaw involves a remote code execution chain enabling administrative takeover and potential cross-tenant access in cloud environments, while a second weakness allows the theft of Looker’s internal management database, exposing credentials and configuration secrets.
Although Google has secured its managed cloud service, organisations running self-hosted or on-premises Looker systems are urged to apply patches immediately and monitor for signs of compromise.
















