Previously harmless Google API keys now expose Gemini AI data

2026-03-04T20:05:55Z6b6a77a6815a1ffca9df3ebe62f164b9fad4dd36d6cbfd23f6b9faffd775e747
CVE-2026-20127apex-oneapi-key-exposurechinese-espionageciscodata-breachdeveloper-targetingfake-repositoriesgeminigoogle-api-keysjuniperjunos-os-evolvedmanomanoptxransomware-trendsrceremote-code-executionrouter-takeoversaas-api-abusesd-wansonicwall-lawsuitsupply-chaintrend-microzero-dayzyxel

What happened

A collection of security news highlighting multiple high-impact incidents and vulnerabilities: publicly exposed Google API keys can now be abused to authenticate to Gemini and access private AI data; Trend Micro patched two critical Apex One RCE vulnerabilities; ManoMano notifies 38 million customers after a third‑party compromise; a critical Juniper PTX Junos OS Evolved flaw can allow unauthenticated remote root takeover; Cisco Catalyst SD‑WAN authentication‑bypass (CVE-2026-20127) has been exploited in zero‑day attacks since 2023; Zyxel disclosed a critical unauthenticated RCE affecting many

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
6b6a77a6815a1ffca9df3ebe62f164b9fad4dd36d6cbfd23f6b9faffd775e747
Enrichment time
2026-03-04T20:05:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.