Switch language한국어
Back to the list

Vercel breach exposes the OAuth gap most security teams cannot detect, scope, or contain

TL;DR AI

Key summary

2 min read
  1. Attackers used a compromised Context.ai account and its OAuth access to enter Vercel internal systems and reach production-related resources.

  2. Vercel said its npm packages were not tampered with, brought in Mandiant, and notified law enforcement.

  3. The company also changed defaults so environment variables are treated as sensitive unless explicitly marked otherwise.

  4. The breach highlights how a single third-party OAuth grant and exposed secrets can bypass traditional security controls.

Read the original