Earlier quoted context omitted.
I wouldn't be extraordinarily surprised if this is the case, but I do not expect it to be as lax as you suggest and given how it's presented to us it reads like someone trying to get people to not look at something. If you have things you can present as evidence that would carry water for your argument, otherwise it's random inflammatory claim on in the internet. And I agree, Google does take security more seriously…
Of the major three cloud providers, Azure is by far the one whose security bugs I hear most about. Not that this necessarily has much relevance to search, but it doesn't inspire confidence in their culture.
Only* about. GCP and AWS haven't had cross-tenant security bugs, meanwhile Azure have had multiple, and trivial ones to boot. If a multitenant service can have such poor security, it's doubtful internal only stuff is any better.