Vulnerabilità · 132 giorni fa
Eliminare una GCP API key non la scollega subito. Questo lascia una finestra breve ma reale in cui una chiave rubata può continuare a funzionare dopo che la console la mostra come rimossa, quindi la risposta standard revoke-and-forget perde la parte che accetta ancora richieste.
3 fonti che coprono questa storia
Deleted Google API keys keep working for up to 23 minutes, researchers warn - Help Net Security
Security researchers found that deleted Google API keys remain valid for up to 23 minutes, leaving a window for attackers to exploit them.
Threat hunters find Google API keys still usable 23 minutes after deletion
Plenty of time for cyber crims to grab data or hit you with a giant bill
Google API Keys Remain Active After Deletion
A security researcher discovered the API keys can still be used for 23 minutes after deletion, even though the cloud provider claims deletion is immediate.
Part of the PlainSec briefing for 2026-05-23