LmCast :: Stay tuned in

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Recorded: Sept. 14, 2026, 1:09 p.m.

Original Summarized

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

News

Featured
Latest

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Artifactory flaws chained in attacks deploying backdoor malware

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

September Windows Server updates break Remote Desktop Services

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Lifetime access to this full cybersecurity bootcamp is only $53 on sale

Microsoft: September updates cause RDS failures on Windows Server

Revolut discloses data breach exposing financial info, passports

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityWebinar: How malicious OAuth apps can lead to Google Workspace breaches

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

By BleepingComputer

September 14, 2026
08:15 AM
0

Google Workspace attackers don't necessarily need to exploit a software vulnerability or steal a user's password to gain access to an organization's data.
On September 23, 2026, BleepingComputer will host a live webinar titled "Breach autopsy: How fast-growing companies are breached through Google Workspace" with Material Security.
The webinar will feature Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC, examining two attacks that used malicious OAuth applications and social engineering to breach Google Workspace environments.
OAuth allows users to grant applications access to Google Workspace data and services without sharing their passwords. While this makes it easier to connect legitimate applications to Google Workspace, attackers can also abuse the authorization process by convincing users to grant permissions to malicious apps.
Rather than stealing credentials, attackers can use social engineering to persuade a target to authorize an application, potentially providing access to sensitive information available through the permissions the user approved.
These attacks highlight why protecting Google Workspace requires organizations to look beyond passwords and traditional authentication controls and understand which applications have access to their environment.
During the webinar, the speakers will break down how the two attacks unfolded, the weaknesses that allowed them to succeed, and the decisions organizations made during the critical first hours of the incidents.
Attendees will also learn which security controls provide the greatest value for fast-growing organizations and what the speakers would prioritize if they were building a Google Workspace security program from scratch.

When attackers convince users to grant access
Social engineering attacks are often associated with tricking users into revealing passwords or other credentials. Malicious OAuth apps provide attackers with another approach: convincing the victim to authorize access instead.
A user may believe they are connecting a legitimate application or responding to a trusted request while actually granting a malicious app permissions within their Google Workspace environment.
The resulting access depends on the permissions granted, but the attack demonstrates why organizations need visibility into third-party applications and the access users are allowed to authorize.
By examining two attacks that combined malicious OAuth applications with social engineering, this webinar will provide a practical look at how these breaches happen and what defenders can do to reduce their exposure.
The upcoming webinar will cover:
How attackers combine social engineering and malicious OAuth applications to target Google Workspace environments
How users can be manipulated into authorizing application access
What happens during the first hours of a Google Workspace breach and which response decisions matter most
Which security controls provide the greatest value for fast-growing companies with limited security resources
Practical security improvements organizations can implement quickly, ranked by effort and potential impact
Join us to see how malicious OAuth applications and social engineering can lead to Google Workspace breaches and what organizations can learn from real-world attacks.
➡ Register now to secure your spot!

Cybersecurity
Data Breach
Data Theft
Material
OAuth
Webinar

Previous Article

Comments have been disabled for this article.

  Upcoming Webinar

Popular Stories

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Hackers abused Claude to extract secrets from 1.8M Android apps

GitLab urges users to patch max severity path traversal flaw

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

Overdue a password health-check? Audit your Active Directory for free

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Attackers targeting Google Workspace environments are leveraging malicious OAuth applications and social engineering techniques to breach organizational data, bypassing reliance on stolen passwords or exploiting direct software vulnerabilities. The mechanism centers on the OAuth authorization process, which permits users to grant applications access to Google Workspace data and services without sharing their credentials. Attackers exploit this system by employing social engineering to persuade users to authorize access to malicious applications, thereby granting the attackers permissions over sensitive information within the Workspace environment. This method shifts the focus of the breach from credential theft to exploiting trust and authorization permissions granted by the end-user.

The webinar presented by Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC, will examine two specific attacks that utilized this combination of malicious OAuth applications and social engineering to compromise Google Workspace systems. The core takeaway is that organizations must adopt a security posture that extends beyond traditional password protection and standard authentication controls to gain visibility into which third-party applications possess access and what permissions users are authorized to grant.

The discussion will detail the sequence of these attacks, analyze the specific weaknesses that enabled the breaches, and assess the critical response decisions made during the initial hours of the incidents. Furthermore, the session aims to provide attendees with actionable knowledge regarding which security controls offer the most significant value for fast-growing organizations with constrained security resources. The presenters will also outline practical security improvements that can be implemented rapidly, ranked by their potential impact and the effort required for deployment. The overarching goal is to equip attendees with a practical understanding of how malicious OAuth applications and social engineering facilitate these breaches and what defensive measures are most effective against them in a real-world context.