Vercel Employee's AI Tool Access Led to Data Breach
ID: 12ae653b-00f9-58c6-bfdd-fde352d5905e
STIX ID: report--12ae653b-00f9-58c6-bfdd-fde352d5905e
Feed Name: Dark Reading
Vercel was breached via stolen OAuth tokens originating from a compromise of Context.ai (an AI tool vendor) allegedly caused by an infostealer bundled with a Roblox cheat; attackers accessed some Vercel environments and environment variables (not marked sensitive) and compromised a limited subset of customer credentials. Vercel and Context are investigating with Mandiant and other responders, customers have been notified and advised to rotate credentials and environment variables, and the incident highlights OAuth tokens and unsanctioned AI tools as critical attack surfaces—organizations are urged to enforce least-privilege, admin-managed consent, and AI governance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
