New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

2026-03-10T13:24:10Z2489b973b9849ff8473e51c8d159ca820b923a95ed9c2944cd35c7e382fabb87
APT28CISA-KEVCVE-2017-7921CVE-2021-22054CVE-2026-20122Chrome-extension-takeoverGoogle Looker StudioLeakyLookerSalesforce-Experience-CloudTenableUNC4899active-exploitationcross-tenantdata-exfiltrationmalicious-npmsupply-chain

What happened

This collection of reports highlights a surge in high-impact vulnerabilities, active exploitation, and widespread malware/espionage activity. Notable items include Tenable’s disclosure of nine “LeakyLooker” cross‑tenant flaws in Google Looker Studio that could enable arbitrary SQL queries and data exfiltration; CISA additions to the KEV catalog (including CVE-2021-22054 and CVE-2017-7921) and Cisco confirmation of active exploitation for CVE-2026-20122; supply-chain and endpoint threats such as a malicious npm package deploying a RAT, Chrome extensions turned malicious after ownership transfer

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2489b973b9849ff8473e51c8d159ca820b923a95ed9c2944cd35c7e382fabb87
Enrichment time
2026-03-10T13:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries · Baitaphish