It is public, so what? Obviously cloud operators consider it secure enough to offer that option by default. What are the reasons to consider it not secure?
If you've managed to breach that and you've got Amazon or Microsoft convinced that you are a privileged account owner, it would be trivial to modify the infrastructure to make a private API endpoint public or create a bastion host with access.