No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Friday, June 19, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Startups

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards

by TheAdviserMagazine
3 weeks ago
in Startups
Reading Time: 3 mins read
A A
A Google Cloud developer woke up to a ,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards
Share on FacebookShare on TwitterShare on LInkedIn


The COO of Google Cloud spent part of last week telling executives that security cannot be bolted onto AI strategies after the fact. The same week, security researchers published findings showing that deleted Google API keys remain usable by attackers for up to 23 minutes, and Google Cloud developers continued seeking refunds for five-figure bills triggered by API calls they never authorized. The gap between the advice and the practice is the story.

Photo by panumas nikhomkhai on Pexels

The prescription

Francis de Souza, Google Cloud’s COO, shared at a recent Los Angeles event that companies need to demand security, governance, and auditability from their platforms from the start, and warned specifically about “shadow AI” — employees reaching for consumer tools without organisational oversight. His framing: “There’s no such thing as an AI strategy without a data strategy and a security strategy. They need to go hand in hand.”

The framing of the threat landscape is equally striking. Google’s own Mandiant M-Trends 2026 report, presented at RSAC, found that adversary coordination has driven the time between initial access and hand-off to a follow-on attacker down to 22 seconds. The implication: human-led defence is structurally too slow. Google Cloud’s proposed answer, articulated at Cloud Next 2026, is a shift from human-in-the-loop to AI-led defence, with humans overseeing rather than operating in the loop.

The practice

While that case was being made, The Register was documenting a different story about the same platform. Prentus CEO Rod Danan watched his Google Cloud bill hit $10,138 in about 30 minutes after attackers used a compromised API key. Sydney-based developer Isuru Fonseka woke up to charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place. Google later reimbursed both after the reporting appeared but said it would not change the underlying policy.

The mechanism is worth pausing on. A February analysis by Truffle Security researcher Joe Leon documented that API keys originally deployed for Google Maps — keys Google’s own documentation told developers to paste publicly into HTML — quietly became capable of accessing Gemini models after Google expanded their scope. Truffle’s scan of public web sources turned up 2,863 live Google API keys exposed to this vector. Separately, Google’s automated systems upgraded users’ billing tiers based on account history, raising effective ceilings as high as $100,000 without explicit consent. Google has indicated it will continue that automatic tier-upgrade policy, citing a preference for preventing service outages over enforcing user-stated budget caps.

The 23-minute window

The credential-revocation issue is the more revealing of the two. Researchers at Aikido Security, led by Joe Leon, found that even developers who catch a compromised key and immediately delete it may not be safe. Across ten controlled trials, the revocation window ranged from about eight minutes to nearly 23, with a median around 16. During that window, success rates are unpredictable — in some minutes, over 90% of requests still authenticated; in others, fewer than 1%. Attackers can use the time to exfiltrate files and cached Gemini conversation data.

Aikido’s analysis indicates that Google’s newer credential formats don’t have the same problem: service account API credentials revoke in about five seconds, and Gemini’s AQ-prefixed key format takes about a minute. Both run at Google scale, suggesting this is technically solvable for standard Google API keys too. Google told Aikido it has no plans to address the gap, closing the report as “Won’t Fix (Infeasible)” and describing the propagation delay as working as intended. The 23-minute window, in other words, is a question of priorities rather than engineering constraint.

Why this matters structurally

The standard reading of incidents like these is that they reflect implementation gaps a large platform will eventually close. The institutional reading is harder. Cloud platforms are simultaneously selling AI infrastructure, AI security tooling, and the analytical frameworks customers use to think about AI risk. The same company that prescribes the standard also defines what counts as meeting it, and operates with internal incentives — uptime, billing continuity, default expansion of API scope — that don’t always align with the customer’s stated security posture.

De Souza himself has been candid that the industry is still figuring this out, telling TechCrunch that everyone is “navigating AI security in real time” and that a sustainable long-term understanding of AI security remains several years away. That is a candid assessment from someone whose job is to have answers.

Silicon Canals has previously examined how the AI industry’s confidence in its own architecture is being quietly walked back in private even as it’s marketed in public. The security layer is following a similar pattern. The advice from platform leaders is sound. The practice on the same platforms is several steps behind the advice. Both things are true, and customers are being asked to act on the prescription while absorbing the cost of the gap.

api key vulnerability
Photo by Tima Miroshnichenko on Pexels



Source link

Tags: APIbillcallscloudDefineDeveloperGoogleMatterspartplatformsrevealsSecuritystandardsWoke
ShareTweetShare
Previous Post

Soroka reconstruction plan comprises five new buildings

Next Post

Rising bond yields and inflation remain key risks for markets: Candace Browning

Related Posts

edit post
People who reach their 60s without close friends aren’t socially deficient, they’re often the ones who spent forty years carrying everyone else’s emotional weight and never had room left to be carried

People who reach their 60s without close friends aren’t socially deficient, they’re often the ones who spent forty years carrying everyone else’s emotional weight and never had room left to be carried

by TheAdviserMagazine
June 19, 2026
0

The standard reading of a friendless sixty-year-old is that something went wrong inside them — a personality too prickly, a...

edit post
I let Chat GPT plan my workdays down to the minute for a week — the shock wasn’t my output, it was realizing how much of my old schedule had been performance

I let Chat GPT plan my workdays down to the minute for a week — the shock wasn’t my output, it was realizing how much of my old schedule had been performance

by TheAdviserMagazine
June 18, 2026
0

By eleven fifteen on the second day, the morning’s writing was done. Not done-for-now, will-come-back-when-I’m-braver. Actually done. The schedule the...

edit post
There’s a particular exhaustion reserved for people who poured their entire twenties into a life they were sure they wanted, only to hit their thirties and discover they’d been chasing someone else’s vision and mistaking it for drive

There’s a particular exhaustion reserved for people who poured their entire twenties into a life they were sure they wanted, only to hit their thirties and discover they’d been chasing someone else’s vision and mistaking it for drive

by TheAdviserMagazine
June 18, 2026
0

I left a finance job in Ireland in my early twenties. The reason was simple enough at the time. I...

edit post
CEO Lesson From My Father: Answer the Call

CEO Lesson From My Father: Answer the Call

by TheAdviserMagazine
June 18, 2026
0

The CEO role is one of ultimate accountability.  Having come from a family business on Main Street (aka Lake Ave),...

edit post
The generation that grew up without seatbelts, without locked doors, and without parents who tracked their afternoons developed a particular relationship to risk that the current world has very little use for, and many of them are quietly mourning a kind of competence nobody asks them to demonstrate anymore

The generation that grew up without seatbelts, without locked doors, and without parents who tracked their afternoons developed a particular relationship to risk that the current world has very little use for, and many of them are quietly mourning a kind of competence nobody asks them to demonstrate anymore

by TheAdviserMagazine
June 18, 2026
0

The same generation that rode in the back of station wagons without seatbelts, drank from garden hoses, and disappeared into...

edit post
Survive Your Startup’s First Few Inspections by Sidestepping These 5 Snags

Survive Your Startup’s First Few Inspections by Sidestepping These 5 Snags

by TheAdviserMagazine
June 17, 2026
0

Inspections can create anxiety for entrepreneurs, prompting late-night searches for receipts before tax audits and rushed site assessments before regulatory...

Next Post
edit post
Rising bond yields and inflation remain key risks for markets: Candace Browning

Rising bond yields and inflation remain key risks for markets: Candace Browning

edit post
Elbit Systems unit buys Israeli AI company

Elbit Systems unit buys Israeli AI company

  • Trending
  • Comments
  • Latest
edit post
Florida Roads Become a Battleground for Illegal Immigration

Florida Roads Become a Battleground for Illegal Immigration

June 9, 2026
edit post
Louisiana’s Age-Tiered Homestead Exemption: 8 Details About the Proposed 2028 Amendment

Louisiana’s Age-Tiered Homestead Exemption: 8 Details About the Proposed 2028 Amendment

June 15, 2026
edit post
The 8 States That Still Tax Social Security in 2026

The 8 States That Still Tax Social Security in 2026

June 6, 2026
edit post
It’s Time To Talk About Massie

It’s Time To Talk About Massie

May 23, 2026
edit post
A Tax on Social Media – Blue-State Governments’ Newest Ploy

A Tax on Social Media – Blue-State Governments’ Newest Ploy

June 5, 2026
edit post
Red Snapper Used as Cudgel by Fed Judge

Red Snapper Used as Cudgel by Fed Judge

May 31, 2026
edit post
Paramount Plus Deal: .99/Month! | Money Saving Mom®

Paramount Plus Deal: $2.99/Month! | Money Saving Mom®

0
edit post
People who reach their 60s without close friends aren’t socially deficient, they’re often the ones who spent forty years carrying everyone else’s emotional weight and never had room left to be carried

People who reach their 60s without close friends aren’t socially deficient, they’re often the ones who spent forty years carrying everyone else’s emotional weight and never had room left to be carried

0
edit post
Fox stock gets sobering BofA call amid Roku deal

Fox stock gets sobering BofA call amid Roku deal

0
edit post
June Fed meeting: Here’s what changed in the new statement

June Fed meeting: Here’s what changed in the new statement

0
edit post
Iran-US sign 14-point deal at Versailles: In 1919, the same place hosted a treaty after World War I that created conditions for World War II

Iran-US sign 14-point deal at Versailles: In 1919, the same place hosted a treaty after World War I that created conditions for World War II

0
edit post
Florida Property Tax Elimination | Florida Homestead Tax

Florida Property Tax Elimination | Florida Homestead Tax

0
edit post
People who reach their 60s without close friends aren’t socially deficient, they’re often the ones who spent forty years carrying everyone else’s emotional weight and never had room left to be carried

People who reach their 60s without close friends aren’t socially deficient, they’re often the ones who spent forty years carrying everyone else’s emotional weight and never had room left to be carried

June 19, 2026
edit post
Slovakia’s Constitutional Court Fires A Warning Shot At Debt Addiction

Slovakia’s Constitutional Court Fires A Warning Shot At Debt Addiction

June 19, 2026
edit post
Iran-US sign 14-point deal at Versailles: In 1919, the same place hosted a treaty after World War I that created conditions for World War II

Iran-US sign 14-point deal at Versailles: In 1919, the same place hosted a treaty after World War I that created conditions for World War II

June 18, 2026
edit post
Trump claims Iran deal is ‘unconditional surrender’: Axios

Trump claims Iran deal is ‘unconditional surrender’: Axios

June 18, 2026
edit post
Inside Trump’s Anthropic crackdown | Fortune

Inside Trump’s Anthropic crackdown | Fortune

June 18, 2026
edit post
How Jim Rowe Filled a Shopping Desert—With Costco Returns

How Jim Rowe Filled a Shopping Desert—With Costco Returns

June 18, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • People who reach their 60s without close friends aren’t socially deficient, they’re often the ones who spent forty years carrying everyone else’s emotional weight and never had room left to be carried
  • Slovakia’s Constitutional Court Fires A Warning Shot At Debt Addiction
  • Iran-US sign 14-point deal at Versailles: In 1919, the same place hosted a treaty after World War I that created conditions for World War II
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.