MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-14 · via BleepingComputer

Upcoming webinar dissects OAuth-based attacks targeting Google Workspace

Image via BleepingComputer
Image via BleepingComputer

A September 23 webinar will examine two real-world incidents where attackers used malicious OAuth applications and social engineering to compromise Google Workspace environments without stealing passwords. The session, hosted by BleepingComputer with Material Security, will break down how the attacks unfolded and highlight security controls that help organizations detect and respond to such threats. Experts will also discuss priorities for building a Google Workspace security program from scratch.

Expanded Detail

The webinar, scheduled for September 23, 2026, is hosted by BleepingComputer in partnership with Material Security. Presenters include Rajan Kapoor, Material Security's Vice President of Security, and Rick Fitzgerald from Fireside Consulting. The session will dissect two real incidents where attackers bypassed traditional credential theft by exploiting OAuth's authorization framework, convincing users to grant permissions to malicious applications. Attendees will examine response decisions made during the critical early hours of each breach, along with practical security controls ranked by effort and impact for organizations with limited resources.

The discussion underscores a growing threat vector: rather than stealing passwords, attackers manipulate the trust users place in application authorization prompts. The webinar aims to equip fast-growing companies with visibility into third-party app access and actionable strategies for building a Google Workspace security program from scratch.

Context

This webinar highlights a shifting threat landscape where attackers increasingly target the authorization layer rather than credentials. Organizations relying solely on traditional authentication controls may face exposure to OAuth-based intrusions, potentially affecting sensitive business data across industries. Small and fast-growing companies with limited security teams could be especially vulnerable, as social engineering tactics exploit human trust in familiar workflows. The insights shared may help defenders prioritize controls and response strategies, though the broader impact depends on how widely such knowledge is adopted across the business community.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Overlooked Third-Party App Permissions in Google Workspace Can Open Doors to Data Breaches · Cybersecurity
Chrome Vulnerability Actively Exploited in the Wild Triggers Emergency Update · Cybersecurity
Quarterly Threat Report Highlights Identity as Primary Attack Vector · Cybersecurity
Attackers exploit account recovery to bypass multi-factor authentication · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Webinar: How malicious OAuth apps can lead to Google Workspace breaches.” Browse more stories.