AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account
ID: 2103b449-af06-565d-91dc-78fd1793b56c
STIX ID: report--2103b449-af06-565d-91dc-78fd1793b56c
Feed Name: The Register (Security)
Threat Score
Vercel suffered an intrusion originating from a compromised employee account (likely via Lumma infostealer) that allowed attackers to hijack Google Workspace access, abuse OAuth, and harvest environment variables and credentials; stolen data — including API keys and employee details — is reported being offered for sale, and Vercel is coordinating remediation with external responders and law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
