No Result
View All Result
  • Login
Tuesday, June 23, 2026
theadvisertimes.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
theadvisertimes.com
No Result
View All Result
Home Startups

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

by theadvisertimes.com
4 weeks ago
in Startups
Reading Time: 3 mins read
A A
0
A Google Cloud developer woke up to a ,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards
Share on FacebookShare on TwitterShare on LInkedIn


The COO of Google Cloud spent part of last week telling executives that security cannot be bolted onto AI strategies after the fact. The same week, security researchers published findings showing that deleted Google API keys remain usable by attackers for up to 23 minutes, and Google Cloud developers continued seeking refunds for five-figure bills triggered by API calls they never authorized. The gap between the advice and the practice is the story.

Photo by panumas nikhomkhai on Pexels

The prescription

Francis de Souza, Google Cloud’s COO, shared at a recent Los Angeles event that companies need to demand security, governance, and auditability from their platforms from the start, and warned specifically about “shadow AI” — employees reaching for consumer tools without organisational oversight. His framing: “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand.”

The framing of the threat landscape is equally striking. Google’s own Mandiant M-Trends 2026 report, presented at RSAC, found that adversary coordination has driven the time between initial access and hand-off to a follow-on attacker down to 22 seconds. The implication: human-led defence is structurally too slow. Google Cloud’s proposed answer, articulated at Cloud Next 2026, is a shift from human-in-the-loop to AI-led defence, with humans overseeing rather than operating in the loop.

The practice

While that case was being made, The Register was documenting a different story about the same platform. Prentus CEO Rod Danan watched his Google Cloud bill hit $10,138 in about 30 minutes after attackers used a compromised API key. Sydney-based developer Isuru Fonseka woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. Google later reimbursed both after the reporting appeared but said it would not change the underlying policy.

The mechanism is worth pausing on. A February analysis by Truffle Security researcher Joe Leon documented that API keys originally deployed for Google Maps — keys Google’s own documentation told developers to paste publicly into HTML — quietly became capable of accessing Gemini models after Google expanded their scope. Truffle’s scan of public web sources turned up 2,863 live Google API keys exposed to this vector. Separately, Google’s automated systems upgraded users’ billing tiers based on account history, raising effective ceilings as high as $100,000 without explicit consent. Google has indicated it will continue that automatic tier-upgrade policy, citing a preference for preventing service outages over enforcing user-stated budget caps.

The 23-minute window

The credential-revocation issue is the more revealing of the two. Researchers at Aikido Security, led by Joe Leon, found that even developers who catch a compromised key and immediately delete it may not be safe. Across ten controlled trials, the revocation window ranged from about eight minutes to nearly 23, with a median around 16. During that window, success rates are unpredictable — in some minutes, over 90% of requests still authenticated; in others, fewer than 1%. Attackers can use the time to exfiltrate files and cached Gemini conversation data.

Aikido’s analysis indicates that Google’s newer credential formats don’t have the same problem: service account API credentials revoke in about five seconds, and Gemini’s AQ-prefixed key format takes about a minute. Both run at Google scale, suggesting this is technically solvable for standard Google API keys too. Google told Aikido it has no plans to address the gap, closing the report as “Won’t Fix (Infeasible)” and describing the propagation delay as working as intended. The 23-minute window, in other words, is a question of priorities rather than engineering constraint.

Why this matters structurally

The standard reading of incidents like these is that they reflect implementation gaps a large platform will eventually close. The institutional reading is harder. Cloud platforms are simultaneously selling AI infrastructure, AI security tooling, and the analytical frameworks customers use to think about AI risk. The same company that prescribes the standard also defines what counts as meeting it, and operates with internal incentives — uptime, billing continuity, default expansion of API scope — that don’t always align with the customer’s stated security posture.

De Souza himself has been candid that the industry is still figuring this out, telling TechCrunch that everyone is “navigating AI security in real time” and that a sustainable long-term understanding of AI security remains several years away. That is a candid assessment from someone whose job is to have answers.

Silicon Canals has previously examined how the AI industry’s confidence in its own architecture is being quietly walked back in private even as it’s marketed in public. The security layer is following a similar pattern. The advice from platform leaders is sound. The practice on the same platforms is several steps behind the advice. Both things are true, and customers are being asked to act on the prescription while absorbing the cost of the gap.

api key vulnerability
Photo by Tima Miroshnichenko on Pexels



Source link

Tags: APIbillcallscloudDefineDeveloperGoogleMatterspartplatformsrevealsSecuritystandardsWoke
ShareTweetShare
Previous Post

Crypto Scammers Exploit Google Ads to Drain $400K From Uniswap Users

Next Post

Elbit Systems unit buys Israeli AI company

Related Posts

We give people a few days and expect them back as themselves, when the science of loss says grief takes no days off at all, and the shame around admitting that is its own quiet cruelty

We give people a few days and expect them back as themselves, when the science of loss says grief takes no days off at all, and the shame around admitting that is its own quiet cruelty

by theadvisertimes.com
June 22, 2026
0

The average bereavement policy in Europe gives employees somewhere between three and five days for the death of an immediate...

Psychology suggests that people who fear AI are often not only afraid of the technology itself — they’re afraid of what it threatens to erase: the status, competence, identity, and sense of usefulness they spent years building.

Psychology suggests that people who fear AI are often not only afraid of the technology itself — they’re afraid of what it threatens to erase: the status, competence, identity, and sense of usefulness they spent years building.

by theadvisertimes.com
June 22, 2026
0

In late 2024, the Pew Research Center surveyed more than 5,000 employed Americans and found that 52 per cent were...

The Weekly Notable Startup Funding Report: 6/22/26 – AlleyWatch

The Weekly Notable Startup Funding Report: 6/22/26 – AlleyWatch

by theadvisertimes.com
June 21, 2026
0

The Weekly Notable Startup Funding Report takes us on a trip across various ecosystems in the US, highlighting some of...

McKinsey’s 2025 global AI survey: 88% of organizations now use AI in at least one function, up from 78% — but most are still stuck in pilot mode, and only a minority can point to any real impact on profit

McKinsey’s 2025 global AI survey: 88% of organizations now use AI in at least one function, up from 78% — but most are still stuck in pilot mode, and only a minority can point to any real impact on profit

by theadvisertimes.com
June 21, 2026
0

Two numbers from McKinsey’s 2025 survey sit awkwardly next to each other. The first is 88 percent, the share of...

The oldest known written customer complaint is a 3,750-year-old clay tablet from ancient Ur, where a furious customer named Nanni accused the merchant Ea-nasir of delivering sub-standard copper — proof that bad reviews are almost as old as writing itself

The oldest known written customer complaint is a 3,750-year-old clay tablet from ancient Ur, where a furious customer named Nanni accused the merchant Ea-nasir of delivering sub-standard copper — proof that bad reviews are almost as old as writing itself

by theadvisertimes.com
June 20, 2026
0

In the British Museum’s Mesopotamian collection sits a palm-sized rectangle of baked clay, catalogued as UET V 81. It is...

I asked ChatGPT why reaching every goal still leaves me flat. The answer wasn’t the one I was expecting.

I asked ChatGPT why reaching every goal still leaves me flat. The answer wasn’t the one I was expecting.

by theadvisertimes.com
June 20, 2026
0

I typed it out plainly: “Based on everything you know about me, why does reaching my goals still leave me...

Next Post
Elbit Systems unit buys Israeli AI company

Elbit Systems unit buys Israeli AI company

How to Plan Your Retirement Using a Pension Calculator

How to Plan Your Retirement Using a Pension Calculator

  • Trending
  • Comments
  • Latest
Should You Offer a Concession to Get Your Apartment Leased Faster?

Should You Offer a Concession to Get Your Apartment Leased Faster?

June 15, 2026
6 Hotels Where Chase’s Points Boost Yields 2.5x

6 Hotels Where Chase’s Points Boost Yields 2.5x

May 22, 2026
Understanding risk remains a major investor blind spot: TIAA Institute

Understanding risk remains a major investor blind spot: TIAA Institute

June 5, 2026
Anthropic’s confidential S-1 signals summer AI IPO race could heat up fast

Anthropic’s confidential S-1 signals summer AI IPO race could heat up fast

June 2, 2026
Memorial Day 2026: Take Advantage of Food Freebies, Deals

Memorial Day 2026: Take Advantage of Food Freebies, Deals

May 23, 2026
9 Best Cheap Cell Phone Plans That Will Save You Money

9 Best Cheap Cell Phone Plans That Will Save You Money

June 3, 2026
7 Benefits of Starting Retirement Savings Early

7 Benefits of Starting Retirement Savings Early

0
Moloco leads group buying 48% stake in AppsFlyer

Moloco leads group buying 48% stake in AppsFlyer

0
CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

0
Trump open to trade talks amid turmoil

Trump open to trade talks amid turmoil

0
52-year-old Outback Steakhouse rival chain closes 24 locations

52-year-old Outback Steakhouse rival chain closes 24 locations

0
Bed Bath & Beyond Combines Stores with Another Chain. See Locations

Bed Bath & Beyond Combines Stores with Another Chain. See Locations

0
7 Benefits of Starting Retirement Savings Early

7 Benefits of Starting Retirement Savings Early

June 23, 2026
CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

June 23, 2026
Moloco leads group buying 48% stake in AppsFlyer

Moloco leads group buying 48% stake in AppsFlyer

June 23, 2026
Syrma SGS Technology shares jump 5% after JV pact with Japan’s Kaga Electronics

Syrma SGS Technology shares jump 5% after JV pact with Japan’s Kaga Electronics

June 23, 2026
Canada’s Inflation Problem Is Far From Over

Canada’s Inflation Problem Is Far From Over

June 23, 2026
China’s 618 shopping festival growth slows sharply as consumer spending malaise persists

China’s 618 shopping festival growth slows sharply as consumer spending malaise persists

June 22, 2026
theadvisertimes.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • 7 Benefits of Starting Retirement Savings Early
  • CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc
  • Moloco leads group buying 48% stake in AppsFlyer
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • About Us
  • Contact Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.