1 of 1
Story summary
- Google LLC faces scrutiny over API key vulnerabilities that could grant unauthorized access to Gemini AI services.
- Researchers from Truffle Security identified over 2,800 exposed keys on public websites, including financial institutions.
- Google LLC acknowledged the issue and has implemented measures to detect and block leaked keys after changes to the Gemini API allowed access.
- Developers should audit their projects and rotate exposed keys to prevent misuse and financial loss.
