Google API Keys Expose Private Data Silently Through Gemini
ID: 1c6a22c3-64ec-5df1-8243-1e7f68598500
STIX ID: report--1c6a22c3-64ec-5df1-8243-1e7f68598500
Feed Name: cybersecurityNews.com
Truffle Security disclosed that legacy Google Cloud API keys historically embedded in public client-side code can silently inherit access to Gemini (Generative Language) endpoints when that API is enabled, allowing attackers to read uploaded files, cached AI context, and incur billable usage. The researchers found 2,863 live vulnerable keys in a Common Crawl scan, affecting organizations including major firms and Google itself, and recommend immediate auditing, rotation, and remediation of unrestricted keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
