Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access
2026-04-09T13:24:12Z•76f4b25b0708eb6f862cbb4de6369e6fb669ceb1611acdce1958a74a70a77a99
adobe-readerandroidapi-keysbitcoin-depotbpo-targetingcredential-theftcrypto-theftdata-breachdata-leakage','dos','patch-management','apache-activemq','rce','eurailexposed-keysgeminigooglemr-raccoonopensslpalo-alto-networkspassport-numberspatchespdf-exploitpiiprivilege-escalationsonicwallunc6783vulnerabilitieszero-day
What happened
Multiple high-impact security events reported: exposed Google API keys embedded in Android apps can be extracted to access Gemini endpoints; Palo Alto Networks and SonicWall released patches for high-severity flaws enabling resource modification and privilege escalation; an Adobe Reader zero-day is being actively exploited. Additional incidents include a Google-flagged UNC6783 campaign targeting BPOs, a 300,000-person Eurail data breach (names and passport numbers), a $3.6M theft from Bitcoin Depot via stolen credentials, OpenSSL fixes for data-leak/DoS issues, and an RCE in Apache ActiveMQ (J
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 76f4b25b0708eb6f862cbb4de6369e6fb669ceb1611acdce1958a74a70a77a99
- Enrichment time
- 2026-04-09T13:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.