
trufflesecurity.com
February 25, 2026
18 min read
78/100
Summary
Google API keys, previously considered non-sensitive, can now be used by Gemini to access private user data. A scan of millions of websites revealed nearly 3,000 Google API keys that were originally deployed for public services.
Key Takeaways
Community Sentiment
Concerns

Google Cloud customer wakes up to $18,000 bill despite $7 budget
Apr 22, 2026

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown
Apr 28, 2026

€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
Apr 16, 2026

Hacking Moltbook
Feb 2, 2026

Addressing Antigravity Bans and Reinstating Access
Feb 28, 2026