Third-party AI hack triggers Vercel breach, internal environments accessed
ID: 72856201-97bf-5a8e-aaa0-7ecefb79cf0c
STIX ID: report--72856201-97bf-5a8e-aaa0-7ecefb79cf0c
Feed Name: Security Affairs
Vercel disclosed a breach originating from a compromised third-party AI tool (Context.ai) that enabled attackers to hijack an employee Google Workspace account and access certain internal environments and non-sensitive environment variables, exposing a limited amount of customer-related data; there is no current evidence that variables marked as sensitive were accessed. Vercel is working with Mandiant and law enforcement, coordinating with Context.ai, and advises customers to check activity logs, rotate exposed secrets, enable stronger protections, and remove a specific suspicious OAuth app ID if present.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
