Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

2026-05-21T20:51:43Z844c71be37c232ea70d075a575b16ad5fbed3ec99b3ab2f9973ba472dc70883f
BigQueryGCPGeminiGoogle-MapsTeamPCPai-assisted-attacksandroid-malwarebanana-rat','brazil-banks','qr-fraud','phishing','remote-access-cloud-securitycode-exfiltrationfileless-malwaregithub-breachgoogle-api-keyskey-revocation-delaylaw-enforcementmshtapremium-smsransomwaresubscription-fraudsupply-chain-compromiseverizon-DBIR-2026vpn-seizurevs-code-extensionvulnerability-exploitationwindows

What happened

Feed of multiple high-impact security stories: Deleted Google API keys remain active for up to 23 minutes after deletion, risking exposure of GCP services including Gemini, BigQuery and Maps; Europol seized the First VPN service used by ransomware gangs, arrested its administrator and obtained user data; a global Android campaign used fake apps to subscribe victims to paid premium-SMS services; legacy MSHTA utility is being abused for stealthy fileless Windows malware; TeamPCP stole ~3,800 internal GitHub repositories via a malicious VS Code extension and is selling the data; Verizon DBIR 2026

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
844c71be37c232ea70d075a575b16ad5fbed3ec99b3ab2f9973ba472dc70883f
Enrichment time
2026-05-21T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds · Baitaphish