Cloud Security · Misconfiguration
Exposed Google API Keys Allow Gemini Access, Billing Abuse Truffle Security found 2,863 public Google Cloud API keys embedded in client-side code that gain access to Gemini after the Generative Language API is enabled.
3 sources · Feb 28
Timeline Sources Feb 28 The Hacker News
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
Research reveals 2,863 public Google API keys can access Gemini endpoints, enabling data exposure and massive billing abuse.
original Feb 27 CSO Online
‘Silent’ Google API key change exposed Gemini AI data
Billing ID keys were turned into Gemini authentication credentials without informing developers.
original Feb 26 BleepingComputer
Previously harmless Google API keys now expose Gemini AI data
Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data.
original Part of the PlainSec briefing for 2026-03-01
Every edition of this story: Exposed Google API Keys Allow Gemini Access, Billing Abuse
Cloud Security · Misconfiguration
Exposed Google API Keys Allow Gemini Access, Billing Abuse Truffle Security found 2,863 public Google Cloud API keys embedded in client-side code that gain access to Gemini after the Generative Language API is enabled.
3 sources · Feb 28
Timeline Sources Feb 28 The Hacker News
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
Research reveals 2,863 public Google API keys can access Gemini endpoints, enabling data exposure and massive billing abuse.
original Feb 27 CSO Online
‘Silent’ Google API key change exposed Gemini AI data
Billing ID keys were turned into Gemini authentication credentials without informing developers.
original Feb 26 BleepingComputer
Previously harmless Google API keys now expose Gemini AI data
Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data.
original Part of the PlainSec briefing for 2026-03-01
Every edition of this story: Exposed Google API Keys Allow Gemini Access, Billing Abuse