Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical, unpatched vulnerability in Google Cloud Config Connector, a Kubernetes add-on used to manage GCP resources, allows an attacker to take full control of cloud accounts and the resources they govern. Researcher Justin O’Leary disclosed the flaw to Google, which acknowledged it but declined to award a bug bounty and has not issued a patch as of June 18, 2026. The incident signals a growing tension between vendor bug bounty programs and responsible disclosure, and raises important questions about the security of infrastructure-as-code tooling that carries elevated cloud IAM permissions.

Author

Tech Jacks Solutions