Skip to main content
Security

Vercel Confirms Breach After OAuth Grant via Compromised AI Vendor

Vercel Confirms Breach After OAuth Grant via Compromised AI Vendor Image: Primary
Vercel, the cloud platform behind Next.js, confirmed on Sunday that attackers gained unauthorized access to internal systems through an OAuth grant tied to a compromised AI vendor. The entry point was Context.ai, an AI tool installed by a Vercel employee who signed into it using a corporate Google Workspace account. When Context.ai was breached, the attacker inherited that employee's Workspace access and pivoted into Vercel environments. Vercel CEO Guillermo Rauch described the attacker as "highly sophisticated and, I strongly suspect, significantly accelerated by AI." The company brought in Mandiant, notified law enforcement, and collaborated with GitHub, Microsoft, npm, and Socket to verify that no Vercel npm packages were compromised. OX Security's analysis found that the attacker escalated privileges by sifting through environment variables not marked as "sensitive." Vercel's bulletin states that variables marked sensitive are stored in a manner that prevents them from being read, while variables without that designation were accessible in plaintext through the dashboard and API. Jaime Blasco, CTO of Nudge Security, independently surfaced a second OAuth grant tied to Context.ai's Google Workspace integration. Vercel said it is now defaulting environment variable creation to "sensitive" and has revoked all active Context.ai OAuth tokens. The incident highlights a broader vulnerability in how companies manage OAuth grants from third-party applications. Nudge Security research indicates the average enterprise has more than 300 SaaS apps with OAuth integrations, many of which receive limited security review.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from VentureBeat, TechCrunch, Engadget and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Google issues Chrome update for actively exploited V8 flaw

Google has released an emergency Chrome update for CVE-2026-85046, a high-severity type-confusion vulnerability in the browser's V8 JavaScript and WebAssembly engine, according to Cybersecurity News. The report says Google is awar...

Capital
Capital

Anthropic nears $15 billion revolver ahead of IPO filing

Anthropic is set to finalize an expansion of its revolving credit facility to $15 billion, according to people familiar with the matter cited by Bloomberg. Morgan Stanley is leading the process, with Goldman Sachs, JPMorgan Chase ...

Infrastructure
Infrastructure

Firmus commits $300 million for Australia-US cable capacity

Australian AI cloud firm Firmus will invest $300 million to secure up to 150Tbps of dedicated capacity for 25 years on SubCo's planned APX East submarine cable system. The 16-fiber-pair cable, first announced in January, is inten...

AI
AI

G42 explores majority US ownership to protect chip access

Abu Dhabi-based AI company G42 has held exploratory talks about potentially selling a majority stake to American companies, according to people familiar with the matter. The reported discussions are aimed at securing the company's...

Infrastructure
Infrastructure

Meta brings Kuna AI-optimized data center online

Meta's Kuna, Idaho, data center is now serving traffic, according to the company's data-center development vice president. The facility is Meta's second AI-optimized site to come online and represents an overall investment of $1.2...

Infrastructure Policy
Infrastructure Policy

Russia bans crypto mining in Moscow region through 2032

Russia's government has banned cryptocurrency mining and mining-pool participation in Moscow, the surrounding region and parts of Kursk through the end of 2032 under Government Decree No. 936. The measure is intended to reduce pre...