Skip to main content
  1. Home
  2. Computing
  3. Android
  4. Apple
  5. Business
  6. Mobile
  7. Web
  8. News

Google's new G Suite security feature lets administrators approve or deny apps

Add as a preferred source on Google

Google is beefing up security for its enterprise G Suite apps with Selective OAuth whitelisting a new feature it announced on Thursday. Starting this week, the Mountain View, California-based search giant will let G Suite administrators specify the third-party apps that are allowed access to a given organization’s data.

“We are constantly evolving and always looking for ways to help our users protect their data,” a Google spokesperson said. “This is just another example of the innovations we are bringing to the table to ensure our customers’ data is secure and protected and can combat new threats as they arise.”

Recommended Videos

The intent is to cut down on security breaches — specifically phishing attacks like those that affected Google Docs users in May — that occur when apps like calendar managers, email clients, and to-do list organizers gain access to apps permissions. When OAuth whitelisting is enabled, G Suite collates all software that’s been approved or denied, and the data it has (or doesn’t have) permission to access. Administrators can see the number of accounts using an app, prevent per-user installs of an app, or impose blanket rules on Gmail, Drive, Calendar, and Contacts.

“OAuth apps whitelisting helps keep your data safe by letting admins specifically select which third-party apps are allowed to access users’ G Suite data,” Google said in a blog post. “[It helps] guard … core G Suite apps data by preventing unauthorized app installs, thus limiting the problems caused by [malicious apps].”

The new per-app controls come on the heels of Google’s other G Suite security enhancements. In May, the company rolled out updated guidelines aimed at tamping down on misleading and spoofed G Suite apps, and began manually reviewing web apps that request user data. And in December 2015, Google launched Data Loss Prevention tools for Gmail and Drive, which automatically scan outgoing emails and shared files for sensitive data and ensure that users can’t send emails that include full Social Security or driver’s license numbers, and other sensitive data.

Google says those and other G Suite preemptive measures, which include machine learning, Safe Browsing warnings about dangerous links, email attachment scanning, and dynamic sign-in challenges, have helped limit the number of users impacted by wide-scale phishing fraud to less than 0.1 percent.

“Protecting your organization’s most sensitive data and assets is a constant challenge,” Google said. “Our teams will continue our constant efforts to support a powerful, useful developer ecosystem that keeps users and their data safe.”

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
The Mac Pro nearly received an M3 Extreme chip twice as powerful as M3 Ultra
High production costs likely killed Apple’s M3 Extreme plans
Apple's Mac Pro on a table at a press event.

Apple discontinued the Mac Pro earlier this year, ending a 20-year run for a computer that once represented the very best of the company’s desktop lineup. However, Apple reportedly had much bigger plans for the machine before ultimately replacing it with the Mac Studio.

According to Bloomberg’s Mark Gurman, Apple developed an M3 Extreme chip that could have offered twice as many CPU and GPU cores as the M3 Ultra. The processor was intended to sit above the Ultra tier and could have finally given the Mac Pro the performance advantage it badly needed. Apple eventually abandoned the chip due to concerns over production costs and limited demand for such an expensive machine.

Read more
Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
Researchers discover AI attack that rewrites an assistant's long-term memory
Chatbot on a smartphone.

Large language models are getting better at remembering us. Whether it's your preferred writing style, recurring tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more personal and useful. But according to new research, that same feature could become one of AI's biggest security vulnerabilities.

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, capable of secretly planting false memories inside AI agents. Rather than stealing information outright, the attack manipulates what an AI remembers, potentially causing it to make dangerous decisions long after the original attack has taken place.

Read more
This experiment shows how easy it is to poison an open-weight AI model for under $100
This research raises new doubts about trusting open weight AI models.
Computer, Electronics, Laptop

Open-weight AI models have been having a moment lately. Just this month, Moonshot's massive Kimi K3 model landed close behind Claude Fable 5 and GPT 5.6 Sol in several benchmarks, all while remaining fully open-weight and downloadable by anyone.

However, Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, managed to poison an open-weight model and proved how easily that openness can be turned against you (via The Register).

Read more