The headline really undersells the point and reads like clickbait. "Things were fine, then she turned the tables. Watch what happens next." I avoided even opening this article several times out of distaste for the headline. It should be something like "Google leaves your Gemini data vulnerable to non-secret API key exploit."
I like their title better than yours which is a bit long and confusing. I personally would like to see more direct wording stating this is s security incident using words like vulnerability or leak etc but the title really is not that bad just that it does not make me want to click. I only clicked because simonw blogged about it.
The headline states a plain fact that is critically important. It's not the writer's fault that the fact is outrageous.
I accused the headline of underselling, not overselling. So unsure why you read me to have blamed the writer for making outrageous claims...