news.mlab.sh
Back to the feed
threat-intel

Google API Keys Remain Active After Deletion

High
Image: Dark Reading
Summary

This article details a significant vulnerability in Google Cloud Platform (GCP) API key deletion processes. Researcher Joe Leon of Aikido Security discovered that API keys can remain active for up to 23 minutes after deletion, creating a window of opportunity for attackers to continue abusing them. This discrepancy between Google’s claims and the actual behavior poses a serious risk to organizations, particularly regarding data exfiltration and unauthorized access, and highlights the need for revised incident response protocols.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.