Next.js developer Vercel warns of customer credential compromise
ID: 67496cdf-1f6d-5233-8077-e6cddf645d5d
STIX ID: report--67496cdf-1f6d-5233-8077-e6cddf645d5d
Feed Name: The Register (Security)
Vercel disclosed an April 19 security incident involving unauthorized access to internal systems that led to credential compromise for a limited set of customers; the company recommended immediate credential rotation and is investigating potential data exfiltration. Context.ai later confirmed a March incident in which compromised OAuth tokens from its consumer AI Office product likely allowed an attacker to access Vercel’s Google Workspace after a Vercel employee granted broad permissions, illustrating risks from third-party integrations and agentic AI services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
