Breaking
Wholesale Trade Survey (monthly): CVs for total sales by geography - June 2026Who’s Tracking You? Use This New Service to Find OutLuigi Mangione pleads guilty in federal case, admits killing insurance CEOBody found stuffed in suitcase in Perak RiverSelepas UFC Freedom, Dana White bayang satu lagi acara megaThe Download: Flock’s new rules, cloning’s future, and children’s cellsUnternehmensinsolvenzen im Mai 2026: -2,0 % gegenüber Mai 2025This scientist is helping build a missing map of childhoodSpeedy Tigers ready to give Germany a tough challenge says CarolanMercedes-Benz CLA 250+ EV now in Malaysia for RM275k: 800V electric sedan with over 700km of rangeBritish cyclist Finlay Tarling dies in Tour of Portugal crash aged 19TNB Electron 120kW DC Charger at McDonald’s Seri Austin, Johor BahruSARIC: the acronym Australia should revive with IndiaGoldman Sachs lifts 12-month target for European stocks on strong earningsPOS Malaysia 2Q Loss Narrows Slightly To RM43 Million On Higher RevenueListrik andal dan energi bersih jadi penopang kenyamanan warga ChinaOUE dips into the red with S$114.6 million loss for H1China Rejects US Statement Over Planned Nature Reserve At South China SeaSemantan valuer: Govt valuation for 1956 compensation is flawedGoogle will now allow users to remove visible watermark from its AI generationsWholesale Trade Survey (monthly): CVs for total sales by geography - June 2026Who’s Tracking You? Use This New Service to Find OutLuigi Mangione pleads guilty in federal case, admits killing insurance CEOBody found stuffed in suitcase in Perak RiverSelepas UFC Freedom, Dana White bayang satu lagi acara megaThe Download: Flock’s new rules, cloning’s future, and children’s cellsUnternehmensinsolvenzen im Mai 2026: -2,0 % gegenüber Mai 2025This scientist is helping build a missing map of childhoodSpeedy Tigers ready to give Germany a tough challenge says CarolanMercedes-Benz CLA 250+ EV now in Malaysia for RM275k: 800V electric sedan with over 700km of rangeBritish cyclist Finlay Tarling dies in Tour of Portugal crash aged 19TNB Electron 120kW DC Charger at McDonald’s Seri Austin, Johor BahruSARIC: the acronym Australia should revive with IndiaGoldman Sachs lifts 12-month target for European stocks on strong earningsPOS Malaysia 2Q Loss Narrows Slightly To RM43 Million On Higher RevenueListrik andal dan energi bersih jadi penopang kenyamanan warga ChinaOUE dips into the red with S$114.6 million loss for H1China Rejects US Statement Over Planned Nature Reserve At South China SeaSemantan valuer: Govt valuation for 1956 compensation is flawedGoogle will now allow users to remove visible watermark from its AI generations
Economy

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]

Source: BleepingComputer · August 14, 2026 at 5:55 PM · AI-assisted report

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Photo: JOestby / CC BY-SA 4.0

KUALA LUMPUR, 15 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Google Workspace Security Under Threat as OAuth Tokens Replace Phishing in Cyberattacks

Market Impact

KUALA LUMPUR, Aug 14 — Cyberattacks on Google Workspace are increasingly bypassing traditional phishing methods, instead exploiting stolen OAuth tokens to gain unauthorized access to Gmail, Drive, and connected systems, according to a report by cybersecurity firm Material Security.

The shift in attack vectors—highlighted in incidents involving companies like Vercel and Composio—signals a broader evolution in cyber threats, where compromised OAuth credentials now serve as the primary entry point rather than email-based credential theft. This trend underscores the need for organizations to adopt security measures that address the entire "workspace attack chain," rather than focusing solely on email protection.

Over the past two months, breaches at Vercel and Composio have demonstrated a recurring pattern: attackers are no longer relying on phishing to infiltrate Google Workspace. Instead, they are leveraging OAuth tokens to access accounts, extract sensitive data from emails and Drive, and move laterally within the system. This method mirrors legitimate AI agent operations, raising concerns about unintended access by automated tools.

Historically, workspace security models have prioritized email as the primary threat vector, assuming that once inside, other components of Google Workspace were relatively secure. However, this assumption is increasingly outdated. Attackers now chain vulnerabilities across the workspace, exploiting OAuth tokens to bypass traditional defenses. The result is a heightened risk of account takeovers (ATOs), where unauthorized access leads to data exfiltration or further compromise.

In Malaysia, where digital transformation and cloud adoption are accelerating, the implications are significant. Businesses relying on Google Workspace for collaboration and data storage must reassess their security postures. The Malaysian Communications and Multimedia Commission (MCMC) has previously emphasized the importance of robust cybersecurity frameworks, particularly as remote work and AI integration become more prevalent.

For Malaysian enterprises, the risks extend beyond external attackers. AI agents—authorized via OAuth tokens—are being integrated into Google Workspace at an unprecedented pace. While these agents are designed to enhance productivity, they often operate with excessive permissions, accessing sensitive data without proper oversight. Unlike human users, AI agents lack the contextual awareness to recognize overprivileged access, potentially leading to unintended data exposure.

Material Security’s analysis highlights that the same security gaps exploited by attackers can be inadvertently triggered by AI agents. For instance, an AI tool granted access to an employee’s inbox may read sensitive content, including password reset links, without triggering traditional security alerts. Without granular controls, organizations risk both malicious exploitation and operational oversights by automated systems.

The report suggests that traditional point solutions—such as standalone email filters or OAuth monitoring tools—are insufficient in addressing this evolving threat landscape. Instead, a unified approach that correlates activity across email, OAuth, Drive, and user behavior is critical. Key recommendations include:

- Enhanced OAuth monitoring: Tracking not just which apps have access, but how they use it, to detect anomalous behavior. - Data visibility and least-privilege access: Identifying where sensitive data resides and restricting access to it, regardless of whether the actor is human or AI-driven. - Content redaction and step-up verification: Blocking access to sensitive information, such as password reset links, until additional verification is completed.

Industry experts in Malaysia have noted the urgency of these measures. "As businesses in Malaysia increasingly adopt cloud-based collaboration tools, the attack surface expands," said a cybersecurity analyst based in Kuala Lumpur. "The shift from phishing to OAuth-based attacks means organizations must adopt a more holistic security strategy."

Looking ahead, the convergence of AI adoption and OAuth-centric attacks is expected to intensify. While AI agents offer productivity gains, their integration into critical systems demands stronger governance and security controls. Organizations that fail to adapt risk falling victim to both malicious actors and unintended AI-driven breaches.

Details not yet available on the specific impact on Malaysian enterprises or government responses. However, the trend underscores the need for proactive measures, including employee training on OAuth permissions and collaboration with cybersecurity firms to implement advanced monitoring solutions.

Related: Google · Kuala Lumpur

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.