logo

Public Google API keys can be used to expose Gemini AI data

ID: df04f105-77ec-5888-aecc-9942fba3d90f

STIX ID: report--df04f105-77ec-5888-aecc-9942fba3d90f

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-02-27

Date Updated: 2026-04-28

...
...

Researchers discovered that many Google Cloud API keys previously considered safe to publish can now be used as credentials for Gemini, with roughly 2,800 live public keys identified (including keys from major firms and Google). This change can let attackers access AI endpoints (potentially reaching data in Docs, Drive, Calendar, etc.) or exhaust cloud billing; the report urges auditing projects for the Generative Language API, checking key restrictions, rotating exposed keys, and monitoring billing and integrations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.