Vercel Confirms Security Breach After Customer Accounts Were Compromised
ID: 10eeee4c-eb99-5414-9427-e69ec7d7ba9a
STIX ID: report--10eeee4c-eb99-5414-9427-e69ec7d7ba9a
Feed Name: Cyber Press
Vercel disclosed an active breach originating from a compromised Context.ai OAuth app that allowed attackers to assume an employee Google Workspace identity, access an employee Vercel account, and enumerate/decrypt non‑sensitive environment variables for a limited subset of customers (potentially exposing API keys, tokens, and credentials). The company published the OAuth client ID for hunting, is collaborating with external responders and law enforcement, has notified impacted customers to rotate secrets and enable stronger protections, and continues to investigate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
