Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Decline of migratory birds spurs calls for coordinated conservation

    September 14, 2026

    Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment

    September 14, 2026

    Did Trump say Republicans are ‘dumbest group of voters’ in 1998?

    September 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Decline of migratory birds spurs calls for coordinated conservation
    • Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment
    • Did Trump say Republicans are ‘dumbest group of voters’ in 1998?
    • ‘Attacks will be fully autonomous’: Russia, Ukraine race towards AI warfare | Russia-Ukraine war News
    • Andy Burnham cancels engagements after death of father
    • Westminster’s time is coming to an end, say first ministers of UK’s Celtic nations | Devolution
    • The future of euro cash: trusted today, designed for tomorrow
    • Why are there concerns AI could threaten humanity?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Webinar: How malicious OAuth apps can lead to Google Workspace breaches

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google Workspace attackers don’t necessarily need to exploit a software vulnerability or steal a user’s password to gain access to an organization’s data.

    On September 23, 2026, BleepingComputer will host a live webinar titled “Breach autopsy: How fast-growing companies are breached through Google Workspace” with Material Security.

    The webinar will feature Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC, examining two attacks that used malicious OAuth applications and social engineering to breach Google Workspace environments.

    OAuth allows users to grant applications access to Google Workspace data and services without sharing their passwords. While this makes it easier to connect legitimate applications to Google Workspace, attackers can also abuse the authorization process by convincing users to grant permissions to malicious apps.

    Rather than stealing credentials, attackers can use social engineering to persuade a target to authorize an application, potentially providing access to sensitive information available through the permissions the user approved.

    These attacks highlight why protecting Google Workspace requires organizations to look beyond passwords and traditional authentication controls and understand which applications have access to their environment.

    During the webinar, the speakers will break down how the two attacks unfolded, the weaknesses that allowed them to succeed, and the decisions organizations made during the critical first hours of the incidents.

    Attendees will also learn which security controls provide the greatest value for fast-growing organizations and what the speakers would prioritize if they were building a Google Workspace security program from scratch.

    Material Webinar

    When attackers convince users to grant access

    Social engineering attacks are often associated with tricking users into revealing passwords or other credentials. Malicious OAuth apps provide attackers with another approach: convincing the victim to authorize access instead.

    A user may believe they are connecting a legitimate application or responding to a trusted request while actually granting a malicious app permissions within their Google Workspace environment.

    The resulting access depends on the permissions granted, but the attack demonstrates why organizations need visibility into third-party applications and the access users are allowed to authorize.

    By examining two attacks that combined malicious OAuth applications with social engineering, this webinar will provide a practical look at how these breaches happen and what defenders can do to reduce their exposure.

    The upcoming webinar will cover:

    • How attackers combine social engineering and malicious OAuth applications to target Google Workspace environments
    • How users can be manipulated into authorizing application access
    • What happens during the first hours of a Google Workspace breach and which response decisions matter most
    • Which security controls provide the greatest value for fast-growing companies with limited security resources
    • Practical security improvements organizations can implement quickly, ranked by effort and potential impact

    Join us to see how malicious OAuth applications and social engineering can lead to Google Workspace breaches and what organizations can learn from real-world attacks.

    ➡ Register now to secure your spot!

    apps Breaches Google lead Malicious OAuth Webinar Workspace
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    CISOs Race to Control AI Agents Without Destroying Their Value

    What the 3M ChatGPT case reveals about AI governance

    Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    Microsoft: September updates break audio on some Windows PCs

    Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Decline of migratory birds spurs calls for coordinated conservation

    September 14, 2026

    Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment

    September 14, 2026

    Did Trump say Republicans are ‘dumbest group of voters’ in 1998?

    September 14, 2026

    ‘Attacks will be fully autonomous’: Russia, Ukraine race towards AI warfare | Russia-Ukraine war News

    September 14, 2026
    Latest Posts

    What Is an Air-Gapped Bitcoin Wallet? Why the Coldcard Exploit Changes the Conversation About Offline Security

    August 3, 2026

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    August 3, 2026

    T-Mobile will give you the new Samsung Galaxy Z Flip for practically nothing if you preorder now

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Decline of migratory birds spurs calls for coordinated conservation

    September 14, 2026

    Germany-UAE energy ties deepen as RWE, Masdar and ADNOC eye LNG supply and €3B offshore wind investment

    September 14, 2026

    Did Trump say Republicans are ‘dumbest group of voters’ in 1998?

    September 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.