Previously harmless Google API keys now expose Gemini AI data
2026-03-04T20:05:55Z•6b6a77a6815a1ffca9df3ebe62f164b9fad4dd36d6cbfd23f6b9faffd775e747
CVE-2026-20127apex-oneapi-key-exposurechinese-espionageciscodata-breachdeveloper-targetingfake-repositoriesgeminigoogle-api-keysjuniperjunos-os-evolvedmanomanoptxransomware-trendsrceremote-code-executionrouter-takeoversaas-api-abusesd-wansonicwall-lawsuitsupply-chaintrend-microzero-dayzyxel
What happened
A collection of security news highlighting multiple high-impact incidents and vulnerabilities: publicly exposed Google API keys can now be abused to authenticate to Gemini and access private AI data; Trend Micro patched two critical Apex One RCE vulnerabilities; ManoMano notifies 38 million customers after a third‑party compromise; a critical Juniper PTX Junos OS Evolved flaw can allow unauthenticated remote root takeover; Cisco Catalyst SD‑WAN authentication‑bypass (CVE-2026-20127) has been exploited in zero‑day attacks since 2023; Zyxel disclosed a critical unauthenticated RCE affecting many
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 6b6a77a6815a1ffca9df3ebe62f164b9fad4dd36d6cbfd23f6b9faffd775e747
- Enrichment time
- 2026-03-04T20:05:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.