Help Net Security: Vercel breached via Context.ai sign-in
Help Net Security ● Covered by 2 sources
Vercel says attackers got in through a hacked Context.ai sign-in and reached some internal systems. A third-party AI tool turned into a back door for customer credentials.
Based on reporting by Help Net Security — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Vercel says a breach at a third-party AI tool, Context.ai, let attackers reach some of its internal systems and a limited set of customer credentials. The company says the incident started when an employee’s Google Workspace account was taken over through a compromised OAuth app tied to Context.ai.
From there, the intruders were able to access some Vercel environments and environment variables that had not been marked sensitive. Vercel says its customer environment variables are encrypted at rest, but it also allows some values to be labeled non-sensitive. That distinction mattered here.
Affected customers were contacted directly and told to rotate credentials and environment variables, review activity logs, check environments for suspicious behavior, rotate Deployment Protection tokens if they use them, and look for unexpected deployments. Vercel also says it added more protections, expanded monitoring, notified law enforcement, and brought in outside experts, including Google Mandiant. It says it has also checked its supply chain and believes Next.js, Turbopack, and its open source projects remain safe.
Context.ai later said it had suffered unauthorized access to its AWS environment and that the attacker likely compromised OAuth tokens for some consumer users. The company said one Vercel employee appears to have signed up with a Vercel enterprise account and granted “Allow All” permissions, which Vercel’s internal OAuth setup then accepted in enterprise Google Workspace.
The breach has also been linked by outside researchers to a specific Chrome extension and OAuth app, and Vercel says the investigation is still ongoing. The company has not ruled out wider impact, and Google Workspace admins have been told to check whether they use the extension and investigate if they do.
My take — AI-written commentary, not fact-checked reporting
This is the boring, expensive truth of modern SaaS: one sloppy third-party permission can punch a hole straight through a much bigger company. Everyone loves the word “ecosystem” until an “Allow All” click turns into an incident response call. The real security feature here is less AI and more people finally getting serious about least privilege.
Read more about this at: Help Net Security