No Result
View All Result
  • Login
Tuesday, August 4, 2026
theadvisertimes.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
theadvisertimes.com
No Result
View All Result
Home Startups

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

by theadvisertimes.com
2 months ago
in Startups
Reading Time: 3 mins read
A A
0
A Google Cloud developer woke up to a ,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards
Share on FacebookShare on TwitterShare on LInkedIn


The COO of Google Cloud spent part of last week telling executives that security cannot be bolted onto AI strategies after the fact. The same week, security researchers published findings showing that deleted Google API keys remain usable by attackers for up to 23 minutes, and Google Cloud developers continued seeking refunds for five-figure bills triggered by API calls they never authorized. The gap between the advice and the practice is the story.

Photo by panumas nikhomkhai on Pexels

The prescription

Francis de Souza, Google Cloud’s COO, shared at a recent Los Angeles event that companies need to demand security, governance, and auditability from their platforms from the start, and warned specifically about “shadow AI” — employees reaching for consumer tools without organisational oversight. His framing: “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand.”

The framing of the threat landscape is equally striking. Google’s own Mandiant M-Trends 2026 report, presented at RSAC, found that adversary coordination has driven the time between initial access and hand-off to a follow-on attacker down to 22 seconds. The implication: human-led defence is structurally too slow. Google Cloud’s proposed answer, articulated at Cloud Next 2026, is a shift from human-in-the-loop to AI-led defence, with humans overseeing rather than operating in the loop.

The practice

While that case was being made, The Register was documenting a different story about the same platform. Prentus CEO Rod Danan watched his Google Cloud bill hit $10,138 in about 30 minutes after attackers used a compromised API key. Sydney-based developer Isuru Fonseka woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. Google later reimbursed both after the reporting appeared but said it would not change the underlying policy.

The mechanism is worth pausing on. A February analysis by Truffle Security researcher Joe Leon documented that API keys originally deployed for Google Maps — keys Google’s own documentation told developers to paste publicly into HTML — quietly became capable of accessing Gemini models after Google expanded their scope. Truffle’s scan of public web sources turned up 2,863 live Google API keys exposed to this vector. Separately, Google’s automated systems upgraded users’ billing tiers based on account history, raising effective ceilings as high as $100,000 without explicit consent. Google has indicated it will continue that automatic tier-upgrade policy, citing a preference for preventing service outages over enforcing user-stated budget caps.

The 23-minute window

The credential-revocation issue is the more revealing of the two. Researchers at Aikido Security, led by Joe Leon, found that even developers who catch a compromised key and immediately delete it may not be safe. Across ten controlled trials, the revocation window ranged from about eight minutes to nearly 23, with a median around 16. During that window, success rates are unpredictable — in some minutes, over 90% of requests still authenticated; in others, fewer than 1%. Attackers can use the time to exfiltrate files and cached Gemini conversation data.

Aikido’s analysis indicates that Google’s newer credential formats don’t have the same problem: service account API credentials revoke in about five seconds, and Gemini’s AQ-prefixed key format takes about a minute. Both run at Google scale, suggesting this is technically solvable for standard Google API keys too. Google told Aikido it has no plans to address the gap, closing the report as “Won’t Fix (Infeasible)” and describing the propagation delay as working as intended. The 23-minute window, in other words, is a question of priorities rather than engineering constraint.

Why this matters structurally

The standard reading of incidents like these is that they reflect implementation gaps a large platform will eventually close. The institutional reading is harder. Cloud platforms are simultaneously selling AI infrastructure, AI security tooling, and the analytical frameworks customers use to think about AI risk. The same company that prescribes the standard also defines what counts as meeting it, and operates with internal incentives — uptime, billing continuity, default expansion of API scope — that don’t always align with the customer’s stated security posture.

De Souza himself has been candid that the industry is still figuring this out, telling TechCrunch that everyone is “navigating AI security in real time” and that a sustainable long-term understanding of AI security remains several years away. That is a candid assessment from someone whose job is to have answers.

Silicon Canals has previously examined how the AI industry’s confidence in its own architecture is being quietly walked back in private even as it’s marketed in public. The security layer is following a similar pattern. The advice from platform leaders is sound. The practice on the same platforms is several steps behind the advice. Both things are true, and customers are being asked to act on the prescription while absorbing the cost of the gap.

api key vulnerability
Photo by Tima Miroshnichenko on Pexels



Source link

Tags: APIbillcallscloudDefineDeveloperGoogleMatterspartplatformsrevealsSecuritystandardsWoke
ShareTweetShare
Previous Post

Crypto Scammers Exploit Google Ads to Drain $400K From Uniswap Users

Next Post

Elbit Systems unit buys Israeli AI company

Related Posts

The Value Creation Engine: How Growth Equity Firms Turn Strategy Into Results

The Value Creation Engine: How Growth Equity Firms Turn Strategy Into Results

by theadvisertimes.com
August 3, 2026
0

You know the pattern. The value creation plan is sharp, the management team agrees, and the initiatives get owners, milestones,...

The idea that Gen Z is lazy misreads the data: full-time workers aged 20 to 24 averaged 40.5 hours a week, and visible enthusiasm is not the same as effort

The idea that Gen Z is lazy misreads the data: full-time workers aged 20 to 24 averaged 40.5 hours a week, and visible enthusiasm is not the same as effort

by theadvisertimes.com
August 3, 2026
0

The 74% figure is real, but it does not mean what the lazy-Gen-Z argument needs it to mean. ResumeBuilder reported...

The 7 Largest NYC Tech Startup Funding Rounds of July 2026 – AlleyWatch

The 7 Largest NYC Tech Startup Funding Rounds of July 2026 – AlleyWatch

by theadvisertimes.com
August 3, 2026
0

New York’s startup ecosystem had another strong month in July 2026, with founders across finance, AI, travel, and healthcare pulling...

People who can’t finish a book they aren’t enjoying aren’t lacking discipline, they’ve quietly figured out that the years remaining are shorter than the years behind, and finishing things out of obligation has stopped feeling like virtue

People who can’t finish a book they aren’t enjoying aren’t lacking discipline, they’ve quietly figured out that the years remaining are shorter than the years behind, and finishing things out of obligation has stopped feeling like virtue

by theadvisertimes.com
August 2, 2026
0

There is a specific kind of freedom that arrives, usually somewhere in the middle of life, when a person closes...

Taking responsibility runs against a built-in bias: we tend to claim our successes and blame circumstances for our failures, and the real skill is owning the part we actually controlled, neither none of it nor all of it

Taking responsibility runs against a built-in bias: we tend to claim our successes and blame circumstances for our failures, and the real skill is owning the part we actually controlled, neither none of it nor all of it

by theadvisertimes.com
August 2, 2026
0

Taking responsibility is one of those virtues we treat as simple. You either own your part or you make excuses,...

A 2022 study tracking university students’ daily experiences for a week found introversion predicted neither preference for nor enjoyment of solitude, while a separate trait, dispositional autonomy, consistently predicted who found time alone enjoyable

A 2022 study tracking university students’ daily experiences for a week found introversion predicted neither preference for nor enjoyment of solitude, while a separate trait, dispositional autonomy, consistently predicted who found time alone enjoyable

by theadvisertimes.com
August 1, 2026
0

The assumption that introverts are the ones who genuinely enjoy time alone, while everyone else merely tolerates it, is common...

Next Post
Elbit Systems unit buys Israeli AI company

Elbit Systems unit buys Israeli AI company

How to Plan Your Retirement Using a Pension Calculator

How to Plan Your Retirement Using a Pension Calculator

  • Trending
  • Comments
  • Latest
SEC pushes private market access, but retail is already in

SEC pushes private market access, but retail is already in

July 16, 2026
Fourth of July 2026 Freebies and Deals

Fourth of July 2026 Freebies and Deals

July 3, 2026
How I Maximize My Sapphire Reserve Dining Credit

How I Maximize My Sapphire Reserve Dining Credit

July 10, 2026
The Weekly Notable Startup Funding Report: 6/22/26 – AlleyWatch

The Weekly Notable Startup Funding Report: 6/22/26 – AlleyWatch

June 21, 2026
The 10 Largest NYC Tech Startup Funding Rounds of June 2026 – AlleyWatch

The 10 Largest NYC Tech Startup Funding Rounds of June 2026 – AlleyWatch

July 6, 2026
The 22 Largest US Funding Rounds of May 2026 – AlleyWatch

The 22 Largest US Funding Rounds of May 2026 – AlleyWatch

June 30, 2026
Philadelphia Fed President Paulson content with current rates, but keeping an open mind

Philadelphia Fed President Paulson content with current rates, but keeping an open mind

0
Will longer retirements shrink the great wealth transfer?

Will longer retirements shrink the great wealth transfer?

0
RESP government grants in Canada: What you’re entitled to in 2026

RESP government grants in Canada: What you’re entitled to in 2026

0
Alphabet (GOOGL): Ausbruch über 376 USD als nächste Kaufchance!

Alphabet (GOOGL): Ausbruch über 376 USD als nächste Kaufchance!

0
If you invested ,000 in gold, Bitcoin and $TRUMP on Inauguration Day, here is what each is worth today

If you invested $1,000 in gold, Bitcoin and $TRUMP on Inauguration Day, here is what each is worth today

0
Will Climate Change Make Homes Uninsurable?

Will Climate Change Make Homes Uninsurable?

0
Will longer retirements shrink the great wealth transfer?

Will longer retirements shrink the great wealth transfer?

August 4, 2026
Philadelphia Fed President Paulson content with current rates, but keeping an open mind

Philadelphia Fed President Paulson content with current rates, but keeping an open mind

August 4, 2026
Alphabet (GOOGL): Ausbruch über 376 USD als nächste Kaufchance!

Alphabet (GOOGL): Ausbruch über 376 USD als nächste Kaufchance!

August 4, 2026
Poolin owes wallet users 3.7M, and its M Texas sale can still unravel next week

Poolin owes wallet users $163.7M, and its $52M Texas sale can still unravel next week

August 4, 2026
Conversations with Frank Fabozzi, Featuring Kari Vatanen

Conversations with Frank Fabozzi, Featuring Kari Vatanen

August 4, 2026
Despite dropping out of MIT to build Stripe, its CEO has a warning for Gen Z who want to copy him

Despite dropping out of MIT to build Stripe, its CEO has a warning for Gen Z who want to copy him

August 4, 2026
theadvisertimes.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Will longer retirements shrink the great wealth transfer?
  • Philadelphia Fed President Paulson content with current rates, but keeping an open mind
  • Alphabet (GOOGL): Ausbruch über 376 USD als nächste Kaufchance!
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • About Us
  • Contact Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.