No Result
View All Result
  • Login
Wednesday, May 27, 2026
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Startups

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

by FeeOnlyNews.com
50 minutes ago
in Startups
Reading Time: 3 mins read
A A
0
A Google Cloud developer woke up to a ,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards
Share on FacebookShare on TwitterShare on LInkedIn


The COO of Google Cloud spent part of last week telling executives that security cannot be bolted onto AI strategies after the fact. The same week, security researchers published findings showing that deleted Google API keys remain usable by attackers for up to 23 minutes, and Google Cloud developers continued seeking refunds for five-figure bills triggered by API calls they never authorized. The gap between the advice and the practice is the story.

Photo by panumas nikhomkhai on Pexels

The prescription

Francis de Souza, Google Cloud’s COO, shared at a recent Los Angeles event that companies need to demand security, governance, and auditability from their platforms from the start, and warned specifically about “shadow AI” — employees reaching for consumer tools without organisational oversight. His framing: “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand.”

The framing of the threat landscape is equally striking. Google’s own Mandiant M-Trends 2026 report, presented at RSAC, found that adversary coordination has driven the time between initial access and hand-off to a follow-on attacker down to 22 seconds. The implication: human-led defence is structurally too slow. Google Cloud’s proposed answer, articulated at Cloud Next 2026, is a shift from human-in-the-loop to AI-led defence, with humans overseeing rather than operating in the loop.

The practice

While that case was being made, The Register was documenting a different story about the same platform. Prentus CEO Rod Danan watched his Google Cloud bill hit $10,138 in about 30 minutes after attackers used a compromised API key. Sydney-based developer Isuru Fonseka woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. Google later reimbursed both after the reporting appeared but said it would not change the underlying policy.

The mechanism is worth pausing on. A February analysis by Truffle Security researcher Joe Leon documented that API keys originally deployed for Google Maps — keys Google’s own documentation told developers to paste publicly into HTML — quietly became capable of accessing Gemini models after Google expanded their scope. Truffle’s scan of public web sources turned up 2,863 live Google API keys exposed to this vector. Separately, Google’s automated systems upgraded users’ billing tiers based on account history, raising effective ceilings as high as $100,000 without explicit consent. Google has indicated it will continue that automatic tier-upgrade policy, citing a preference for preventing service outages over enforcing user-stated budget caps.

The 23-minute window

The credential-revocation issue is the more revealing of the two. Researchers at Aikido Security, led by Joe Leon, found that even developers who catch a compromised key and immediately delete it may not be safe. Across ten controlled trials, the revocation window ranged from about eight minutes to nearly 23, with a median around 16. During that window, success rates are unpredictable — in some minutes, over 90% of requests still authenticated; in others, fewer than 1%. Attackers can use the time to exfiltrate files and cached Gemini conversation data.

Aikido’s analysis indicates that Google’s newer credential formats don’t have the same problem: service account API credentials revoke in about five seconds, and Gemini’s AQ-prefixed key format takes about a minute. Both run at Google scale, suggesting this is technically solvable for standard Google API keys too. Google told Aikido it has no plans to address the gap, closing the report as “Won’t Fix (Infeasible)” and describing the propagation delay as working as intended. The 23-minute window, in other words, is a question of priorities rather than engineering constraint.

Why this matters structurally

The standard reading of incidents like these is that they reflect implementation gaps a large platform will eventually close. The institutional reading is harder. Cloud platforms are simultaneously selling AI infrastructure, AI security tooling, and the analytical frameworks customers use to think about AI risk. The same company that prescribes the standard also defines what counts as meeting it, and operates with internal incentives — uptime, billing continuity, default expansion of API scope — that don’t always align with the customer’s stated security posture.

De Souza himself has been candid that the industry is still figuring this out, telling TechCrunch that everyone is “navigating AI security in real time” and that a sustainable long-term understanding of AI security remains several years away. That is a candid assessment from someone whose job is to have answers.

Silicon Canals has previously examined how the AI industry’s confidence in its own architecture is being quietly walked back in private even as it’s marketed in public. The security layer is following a similar pattern. The advice from platform leaders is sound. The practice on the same platforms is several steps behind the advice. Both things are true, and customers are being asked to act on the prescription while absorbing the cost of the gap.

api key vulnerability
Photo by Tima Miroshnichenko on Pexels



Source link

Tags: APIbillcallscloudDefineDeveloperGoogleMatterspartplatformsrevealsSecuritystandardsWoke
ShareTweetShare
Previous Post

Paxton Win in Texas Cements the MAGA Shift

Related Posts

How AI Video Is Evolving — And the Startups Leading the Charge

How AI Video Is Evolving — And the Startups Leading the Charge

by FeeOnlyNews.com
May 26, 2026
0

For years, AI video has chased realism. We’re talking sharper frames, smoother motion, fewer artifacts. In many respects, that baseline...

A one-person startup just raised M at a 0M valuation, and it explains ClickUp’s 22% layoff

A one-person startup just raised $30M at a $250M valuation, and it explains ClickUp’s 22% layoff

by FeeOnlyNews.com
May 26, 2026
0

ClickUp’s 22% layoff is being sold as an AI transformation. The more honest reading is that it’s a performance staged...

The Weekly Notable Startup Funding Report: 5/25/26 – AlleyWatch

The Weekly Notable Startup Funding Report: 5/25/26 – AlleyWatch

by FeeOnlyNews.com
May 25, 2026
0

The Weekly Notable Startup Funding Report takes us on a trip across various ecosystems in the US, highlighting some of...

The economist John Maynard Keynes predicted in 1930 that his grandchildren would be working roughly fifteen hours a week by the early twenty-first century — and the strange thing is that, technologically, he was approximately correct

The economist John Maynard Keynes predicted in 1930 that his grandchildren would be working roughly fifteen hours a week by the early twenty-first century — and the strange thing is that, technologically, he was approximately correct

by FeeOnlyNews.com
May 25, 2026
0

It is unusual for a prediction to be half right and half wrong at the same time, but that is...

Spotify and Universal Music struck a deal to let Premium users make AI covers of UMG songs

Spotify and Universal Music struck a deal to let Premium users make AI covers of UMG songs

by FeeOnlyNews.com
May 22, 2026
0

Spotify and Universal Music Group have struck a licensing agreement that will let Premium subscribers create AI-generated covers and remixes...

SpaceX IPO filing lays out a .75 trillion bet on Mars, AI and Musk control

SpaceX IPO filing lays out a $1.75 trillion bet on Mars, AI and Musk control

by FeeOnlyNews.com
May 22, 2026
0

SpaceX is not really selling rockets. At a proposed $1.75 trillion valuation, with Elon Musk locking in just over 85%...

  • Trending
  • Comments
  • Latest
10 States Offering Free or Low‑Cost College Courses for Residents Over 60

10 States Offering Free or Low‑Cost College Courses for Residents Over 60

May 13, 2026
The New Medicare Coding Change Confusing Pharmacies Across Multiple States

The New Medicare Coding Change Confusing Pharmacies Across Multiple States

May 11, 2026
Week 14: A Peek Into This Past Week + What I’m Reading, Listening to, and Watching!

Week 14: A Peek Into This Past Week + What I’m Reading, Listening to, and Watching!

April 6, 2026
Memorial Day 2026: Take Advantage of Food Freebies, Deals

Memorial Day 2026: Take Advantage of Food Freebies, Deals

May 23, 2026
Latam Insights: Coinbase Co-Founder Eyes Venezuela as Grupo Salinas Embraces Stablecoins

Latam Insights: Coinbase Co-Founder Eyes Venezuela as Grupo Salinas Embraces Stablecoins

May 17, 2026
The 18 Largest US Funding Rounds of April 2026 – AlleyWatch

The 18 Largest US Funding Rounds of April 2026 – AlleyWatch

May 15, 2026
We Tried Disney’s Revamped Rides. Here’s How it Went.

We Tried Disney’s Revamped Rides. Here’s How it Went.

0
A Google Cloud developer woke up to a ,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

0
Streamlining Partner Communications: A Strategic Guide for 2026

Streamlining Partner Communications: A Strategic Guide for 2026

0
Like Bill Gates, this billionaire is capping his kids’ inheritance at 8 figures

Like Bill Gates, this billionaire is capping his kids’ inheritance at 8 figures

0
Cybersecurity stocks are surging. One looks promising into earnings

Cybersecurity stocks are surging. One looks promising into earnings

0
Paxton Win in Texas Cements the MAGA Shift

Paxton Win in Texas Cements the MAGA Shift

0
A Google Cloud developer woke up to a ,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

May 27, 2026
Paxton Win in Texas Cements the MAGA Shift

Paxton Win in Texas Cements the MAGA Shift

May 27, 2026
Like Bill Gates, this billionaire is capping his kids’ inheritance at 8 figures

Like Bill Gates, this billionaire is capping his kids’ inheritance at 8 figures

May 27, 2026
Ethereum OG Sitting On 630,000% Gain Awakens After 10 Years

Ethereum OG Sitting On 630,000% Gain Awakens After 10 Years

May 27, 2026
ONGC shares fall 4% despite 46% YoY jump in Q4 profit; revenue rises 4%

ONGC shares fall 4% despite 46% YoY jump in Q4 profit; revenue rises 4%

May 27, 2026
We Tried Disney’s Revamped Rides. Here’s How it Went.

We Tried Disney’s Revamped Rides. Here’s How it Went.

May 26, 2026
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards
  • Paxton Win in Texas Cements the MAGA Shift
  • Like Bill Gates, this billionaire is capping his kids’ inheritance at 8 figures
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.