LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
breach

The modern attack chain: Rethinking Google Workspace security in the age of AI

Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incidents. They’re the same attack, run twice, against different targets, where email was not the entry point into the workspace. And once you see the pattern clearly

zeroday.news ·

Recent cybersecurity incidents involving Vercel and Composio have revealed an evolving attack chain targeting Google Workspace, where initial compromise often bypasses traditional email-centric defenses. This new pattern, which leverages stolen OAuth tokens as an entry point, mirrors the operational model of legitimate AI agents, raising concerns about unintended data exposure even without malicious intent.

Historically, the dominant model for Workspace security focused on email as the primary threat vector, with phishing attacks leading to credential theft and subsequent account takeover (ATO). In this "old" model, a malicious email would initiate the attack, leading to stolen credentials, access to sensitive data in Gmail and Drive, lateral movement through password resets or "magic links" to other applications, and ultimately, persistent access for data exfiltration.

However, the Vercel and Composio breaches illustrate a shift where the attack sequence is inverted. Instead of email being the entry point, a stolen OAuth token establishes initial persistence. These tokens are particularly insidious because they can survive password resets, do not expire, and are often invisible to users and many security teams not specifically monitoring application behavior. This method effectively constitutes a supply chain attack, where a compromised third-party supplier grants access to the target environment.

Once an attacker obtains an OAuth token, they gain access to sensitive data within Gmail and Google Drive. The account takeover is then executed using this OAuth access, transforming a compromised inbox into a broader incident. From there, attackers can move laterally across connected systems by exploiting credentials found in Drive or by initiating password resets and using magic links via the now-controlled email account.

This OAuth-centric attack chain bears a striking resemblance to how legitimate AI agents operate within Google Workspace. Employees are increasingly connecting AI agents to their Workspace environments, granting them legitimate OAuth permissions to read emails, search Drive, and perform tasks on their behalf. These agents, by design, use OAuth grants to access data and take actions.

The concern arises when an AI agent, even without malicious intent, behaves unexpectedly due to ambiguous instructions, unforeseen reasoning paths, or prompts encountered within the environment. Such an agent could inadvertently follow the same path as an attacker: accessing an inbox or Drive folder beyond its explicit task scope, reading sensitive content like credentials or confidential documents, and then taking actions downstream, potentially leading to lateral movement across applications and unintended data exfiltration to third parties.

Unlike human operators who might exercise common sense or adhere to company policies when over-permissioned, an AI agent granted broad OAuth tokens will simply execute its task based on its programming, without understanding if it has been granted excessive permissions. This means the risk isn't necessarily about an agent being weaponized or experiencing prompt injection, but rather about an agent operating exactly as designed within an environment lacking appropriate guardrails.

Therefore, effective defense strategies must shift from solely focusing on agent-specific controls to implementing robust environmental controls. This includes identifying where sensitive data resides across email and Drive to enforce restrictive access policies, thoroughly investigating OAuth grants to understand and limit exposure, and implementing measures like redacting password reset links or requiring step-up verification for sensitive inbox content. These controls would protect against both sophisticated attackers leveraging OAuth and legitimate AI agents acting outside their intended scope, addressing what is fundamentally the same security challenge.

breachai
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Mythos has made 2026 patching hell. It might make 2027 a breeze

Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner

vulnerability

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written in YAML, the code is Python 3.11 and up. Rehman Ahmadzai, who maintains the project, said DeepZero h

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76