logo

Context.ai OAuth Token Compromise

ID: 6ca651ff-cc35-5045-ab1e-4a5e407fba5d

STIX ID: report--6ca651ff-cc35-5045-ab1e-4a5e407fba5d

Feed Name: Wiz Blog

Threat Score
72/100

Date Published: 2026-04-20

Date Updated: 2026-05-01

...
...

On April 19, 2026 Vercel disclosed an incident in which an attacker used compromised OAuth tokens from Context.ai to access an employee’s Google Workspace and potentially downstream customer resources; Context.ai confirmed consumer OAuth tokens were likely compromised. The report frames this as a double supply‑chain OAuth compromise, provides a verified OAuth client ID IoC, investigative queries and remediation steps for Google Workspace, Entra ID, and Okta, and notes an unconfirmed report that an infostealer infection at Context.ai may have enabled the theft of OAuth credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.