Ensure there are no unrestricted API keys available within your GCP project.
To reduce the risk of attacks, Google Cloud API keys should be restricted to only call the APIs needed by your application.
Ensure that API restrictions are set for all Google Cloud API Keys.