Webinar: How malicious OAuth apps can lead to Google Workspace breaches
2026-09-14T13:23:23Z•0f6869c30d554e99d3722f1da35cd78e114d400ce6785243be1f4a9936468d05
CVE-2026-51990CVE-2026-85102CVE-2026-85103CVE-2026-85706AI platform abuseCISACheck Point VPNGitLabGoogle WorkspaceGrayRabbitJFrog ArtifactoryMicrosoft 365OAuth abuseTencent Sogou Input MethodWindows Serveractive exploitationcredential theftcritical vulnerabilitiesdata breachpasskeyspath traversalphishingremote access VPNsupply chain
What happened
BleepingComputer security news covers active exploitation of critical vulnerabilities in GitLab, Check Point VPN, Tencent Sogou Input Method, and JFrog Artifactory; phishing and malicious OAuth campaigns targeting Google Workspace, Microsoft 365, and Trezor users; data breaches involving Revolut and Florida's DMV; AI platform abuse; and Microsoft update-related failures. Immediate patching and heightened monitoring are warranted for affected internet-facing products and identity platforms.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0f6869c30d554e99d3722f1da35cd78e114d400ce6785243be1f4a9936468d05
- Enrichment time
- 2026-09-14T13:23:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.