Cloud Security · Misconfiguration

Exposed Google API Keys Allow Gemini Access, Billing Abuse

Truffle Security found 2,863 public Google Cloud API keys embedded in client-side code that gain access to Gemini after the Generative Language API is enabled.

3 sources · Feb 28

Timeline

Sources

Part of the PlainSec briefing for 2026-03-01

Every edition of this story: Exposed Google API Keys Allow Gemini Access, Billing Abuse