Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Data Breaches & Incidents
  5. đź”´ Critical: Webinar: How Google Workspace breaches happen and what to do next

đź”´ Critical: Webinar: How Google Workspace breaches happen and what to do next

Scheduled Pinned Locked Moved Data Breaches & Incidents
google
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Most Google Workspace compromises don’t start with a clever exploit or zero-day. Instead, they typically begin with social engineering—phishing, credential theft, or session hijacking—or with forgotten third-party integrations that retain excessive permissions long after they’re needed.

    The webinar walks through real-world breach scenarios, focusing on what occurs in the critical first hours after an attacker gains access. That early window often determines whether an incident stays contained or spirals into full account takeover, data exfiltration, or lateral movement across connected services.

    Key technical points covered include:

    • The role of OAuth applications and legacy integrations in providing persistent, hidden access to Workspace data.
    • How attackers use session tokens and cookies to bypass MFA (multi-factor authentication) after an initial login.
    • The importance of auditing delegated admin roles and API scopes, since many breaches exploit over-privileged accounts.
    • Detection gaps in default Workspace logging—specifically, which logs (like login challenges or Gmail message search events) are not enabled by default.

    The discussion also emphasizes practical controls that make the biggest impact: enforcing hardware-key-only MFA, restricting third-party app access via allowlisting, and setting up custom alerts for unusual admin actions or impossible travel patterns. The earlier you identify abnormal behavior, the more likely you can revoke access before damage spreads.

    Source: BleepingComputer

    Given how often these breaches rely on stale OAuth permissions, how is your organization tracking and revoking access for legacy third-party apps in Workspace?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better đź’—

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World