Old Google API Keys Expose Sensitive Data via Gemini Access

Old Google API Keys Expose Sensitive Data via Gemini Access

First seen 26 Feb 2026, 14:14 UTC News.YcombinatorCybernewsBleepingcomputerCybersecuritynewsC3.Unu.Edu+7 83% similarity 29.2

Article Content

Browse articles
ThreatCluster

Old Google API keys, previously deemed harmless, now pose a security risk as they can access sensitive data through the Gemini API. Security researchers found that nearly 3,000 keys, originally used for public services, can authenticate to Gemini, allowing potential attackers to access private data. This shift in functionality has raised alarms among developers and security experts.

ThreatCluster AI

Timeline

2026-02-25
Discovery of API keys' new access capabilities reported
2026-02-26
Cybernews article published on the risk of old API keys

Community

Browse all →