New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries
2026-03-10T13:24:10Z•2489b973b9849ff8473e51c8d159ca820b923a95ed9c2944cd35c7e382fabb87
APT28CISA-KEVCVE-2017-7921CVE-2021-22054CVE-2026-20122Chrome-extension-takeoverGoogle Looker StudioLeakyLookerSalesforce-Experience-CloudTenableUNC4899active-exploitationcross-tenantdata-exfiltrationmalicious-npmsupply-chain
What happened
This collection of reports highlights a surge in high-impact vulnerabilities, active exploitation, and widespread malware/espionage activity. Notable items include Tenable’s disclosure of nine “LeakyLooker” cross‑tenant flaws in Google Looker Studio that could enable arbitrary SQL queries and data exfiltration; CISA additions to the KEV catalog (including CVE-2021-22054 and CVE-2017-7921) and Cisco confirmation of active exploitation for CVE-2026-20122; supply-chain and endpoint threats such as a malicious npm package deploying a RAT, Chrome extensions turned malicious after ownership transfer
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2489b973b9849ff8473e51c8d159ca820b923a95ed9c2944cd35c7e382fabb87
- Enrichment time
- 2026-03-10T13:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.