Switch language한국어
Back to the list

Vercel Hacked: The Story Behind the Attack

TL;DR AI

Key summary

2 min read
  1. Vercel said a third-party AI tool’s compromised OAuth credentials were used to access an employee’s Google Workspace account.

  2. The attacker escalated privileges inside internal systems and viewed environment variables that were not classified as sensitive.

  3. Vercel said encrypted secret variables were not accessed, and its open-source projects such as Next.js and Turbopack were unaffected.

  4. The incident highlights how third-party OAuth access and weak secret classification can widen the impact of a single compromise.

Read the original