Vercel Confirms Security Breach – Set of Customer Account Compromised
ID: e56322ce-fe58-5ac8-a136-9cf99c3441f6
STIX ID: report--e56322ce-fe58-5ac8-a136-9cf99c3441f6
Feed Name: cybersecurityNews.com
Vercel disclosed a supply-chain OAuth compromise originating from a Lumma Stealer infection on a Context.ai employee machine that allowed attackers to harvest OAuth tokens, hijack a Vercel employee Google Workspace account, and access/decrypt non-sensitive environment variables for a subset of customers; ShinyHunters has claimed responsibility and Vercel published an OAuth App Client ID IOC while urging customers to rotate credentials, enable MFA, and mark secrets as sensitive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
