Generative AI Rollout Exposes Hidden Risk in Google Cloud API Keys

Generative AI Rollout Exposes Hidden Risk in Google Cloud API Keys

A quiet change in how Google’s cloud services interact has opened an unexpected security gap, putting thousands of organisations at risk of data exposure and mounting AI bills. Security researchers have found that publicly visible Google API keys, once considered low risk, can now be used to access Gemini AI if the generative AI service is enabled in the same cloud project.

Nearly 3,000 such keys are estimated to be active across websites and public code repositories, including those linked to financial institutions, technology firms, and recruitment platforms.

For years, developers embedded these keys in apps and webpages for services like Maps or Firebase, relying on Google’s guidance that they were not sensitive credentials. That assumption no longer holds.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *