Researcher discovered access to non-production Google App Engine environments and internal APIs. This allowed configuring internal settings like Service Account IDs and quotas. Google considered it RCE due to their infrastructure. Access was blocked and a $36,337 reward issued.
Monitor for unexpected access attempts to non-production App Engine environments. Review App Engine configuration changes, especially around Service Accounts and quotas.