Webinar: How malicious OAuth apps can lead to Google Workspace breaches

2026-09-14T13:23:23Z•0f6869c30d554e99d3722f1da35cd78e114d400ce6785243be1f4a9936468d05
CVE-2026-51990CVE-2026-85102CVE-2026-85103CVE-2026-85706AI platform abuseCISACheck Point VPNGitLabGoogle WorkspaceGrayRabbitJFrog ArtifactoryMicrosoft 365OAuth abuseTencent Sogou Input MethodWindows Serveractive exploitationcredential theftcritical vulnerabilitiesdata breachpasskeyspath traversalphishingremote access VPNsupply chain

What happened

BleepingComputer security news covers active exploitation of critical vulnerabilities in GitLab, Check Point VPN, Tencent Sogou Input Method, and JFrog Artifactory; phishing and malicious OAuth campaigns targeting Google Workspace, Microsoft 365, and Trezor users; data breaches involving Revolut and Florida's DMV; AI platform abuse; and Microsoft update-related failures. Immediate patching and heightened monitoring are warranted for affected internet-facing products and identity platforms.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0f6869c30d554e99d3722f1da35cd78e114d400ce6785243be1f4a9936468d05
Enrichment time
2026-09-14T13:23:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Webinar: How malicious OAuth apps can lead to Google Workspace breaches · Baitaphish