The source describes two attacks in which malicious OAuth applications are paired with social engineering. The aim is access to Google Workspace data, and the source says this can happen without relying solely on stolen passwords. The webinar is framed around how these breaches unfold and which security controls can help stop them. For small teams, the practical takeaway is to treat third-party app permissions as part of the Workspace attack surface.
Security Brief/Report
GitLab patches maximum-severity path traversal flaw, urges self-managed users to upgrade
GitLab released fixes for a maximum-severity path traversal vulnerability, CVE-2026-85706, and a second critical flaw, CVE-2026-87719. The company urged self-managed installations to upgrade immediately,…
