logo

Next.js developer Vercel warns of customer credential compromise

ID: 67496cdf-1f6d-5233-8077-e6cddf645d5d

STIX ID: report--67496cdf-1f6d-5233-8077-e6cddf645d5d

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2026-04-20

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Vercel disclosed an April 19 security incident involving unauthorized access to internal systems that led to credential compromise for a limited set of customers; the company recommended immediate credential rotation and is investigating potential data exfiltration. Context.ai later confirmed a March incident in which compromised OAuth tokens from its consumer AI Office product likely allowed an attacker to access Vercel’s Google Workspace after a Vercel employee granted broad permissions, illustrating risks from third-party integrations and agentic AI services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.