logo

Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement

ID: efd4c75e-9353-5d5d-b1c1-caaf4b5f498d

STIX ID: report--efd4c75e-9353-5d5d-b1c1-caaf4b5f498d

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-02-28

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

New research from Truffle Security (and corroborating findings from Quokka) shows thousands of Google Cloud API keys embedded in client-side code and mobile apps can be abused to access Gemini/Generative Language API endpoints when that API is enabled on a project; attackers scraping public sites or repos can use those keys to access uploaded or cached contents and run LLM calls that incur large charges. The default creation of "Unrestricted" keys and retroactive granting of Gemini privileges amplified exposure; Google has implemented mitigations to detect and block leaked keys, and users are advised to audit enabled AI APIs and rotate exposed keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.