Vercel Confirms Cyber Incident After Sophisticated Attacker Exploits Third‑Party Tool
ID: f8c6631a-9a64-59eb-9a97-c21f25ba1ce7
STIX ID: report--f8c6631a-9a64-59eb-9a97-c21f25ba1ce7
Feed Name: Infosecurity Magazine (News)
Vercel confirmed a breach stemming from a third-party OAuth integration (Context.ai) that allowed a sophisticated attacker to hijack an employee Google Workspace account, access some internal environments and non-sensitive environment variables, and claim possession of API keys, tokens, source code and databases while demanding $2M; Vercel is working with Mandiant, says sensitive variables and npm packages appear uncompromised, and has advised customers to enable MFA, rotate exposed variables and review deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
