A significant vulnerability has been found in the OverlayFS component of Ubuntu's Linux kernel, specifically affecting versions used on Google Cloud Platform. The flaw could allow a local attacker to bypass permission checks and gain elevated system privileges, posing a serious security risk for affected servers.
A critical vulnerability, dubbed 'Copy Fail,' has been discovered in the Linux kernel for Google Cloud Platform. The flaw allows local attackers to escalate privileges or escape containers. Several other security issues were also patched, which could have allowed system compromise. Users should update their systems immediately.
Google Cloud is introducing a new way to manage planned maintenance. Instead of tracking individual resource updates across many projects, teams can now view maintenance events in the context of their business services. This change aims to reduce operational overhead for platform and SRE teams.
LivePerson significantly cut its Logstash processing costs on Google Cloud by over 50%. The company achieved this by systematically benchmarking GCP machine types, ultimately switching to AMD Milan-based instances. They also found that Kafka compression codec selection independently boosted throughput.
Google Cloud has announced the general availability of its managed Remote MCP Server for AlloyDB. This new service provides a direct and secure connection for AI models and agents to access real-time data stored in AlloyDB databases, improving the quality of context for AI-powered applications.
Snowflake's platform on Google Cloud in Melbourne has successfully completed an IRAP assessment, meeting the Australian Government's 'Protected' security standard. This certification allows public sector agencies and regulated industries in Australia to use the data platform for handling sensitive information and critical workloads on GCP.
Railway, a developer platform, experienced an eight-hour, platform-wide outage affecting 3 million users. The cause was an automated, unannounced suspension of its production account by Google Cloud. The incident highlighted the risks of hosting a critical control plane on a single cloud provider, even with multi-cloud workloads.